S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-19915 Scanner

CVE-2018-19915 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19915
4.8
CVSS

DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DomainMOD is a web-based domain name management software that allows users to manage their domain portfolios, whois records, DNS records, and SSL certificates from a single centralized platform. It offers features such as domain name registration, bulk domain management, and automated domain expiry notifications.

However, the software has recently been found to have a security vulnerability- CVE-2018-19915. This vulnerability arises when attackers inject malicious code into the "Web Host Name" or "Web Host URL" fields in the "assets/edit/host.php" section.

When this vulnerability is exploited, it can lead to the injection of malicious code into a user's website, which can compromise the security of their entire domain name management system. This can result in the unauthorized access to sensitive data, website defacement, hijacking, and even complete system takeover.

Finally, readers of this article can benefit from the pro features of s4e.io, which offer quick and easy identification of security vulnerabilities in their digital assets. With this platform, users can detect vulnerabilities before they pose a threat and take proactive measures to protect their systems. s4e.io offers a complete vulnerability management solution, providing users with the peace of mind they need to focus on other aspects of managing their digital assets.

 

REFERENCES

Solution Advice

To mitigate the risks associated with this vulnerability, DomainMOD users can take the following steps:

  • Update their DomainMOD software to version 4.11.02, which addresses the vulnerability issue.
  • Avoid using untrusted inputs into the "Web Host Name" or "Web Host URL" fields.
  • Use a web application firewall (WAF) to detect and prevent XSS attacks.
  • Train employees on how to identify and respond to phishing attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-19915 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD | S4E