S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-20010 Scanner

CVE-2018-20010 scanner - Cross-Site Scripting (XSS) vulnerability in DomainMOD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-20010
4.8
CVSS

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DomainMOD is an open-source web application that is used as an all-in-one solution for the management of domain names, websites, and SSL certificates. It offers a variety of features, including domain management, user management, bulk updates, and template-based automation to simplify the process of managing digital assets. This application aims to make it easier for website and domain owners to manage their digital assets from a single platform.

However, DomainMOD 4.11.01 has been found to have a critical vulnerability, CVE-2018-20010. This vulnerability allows attackers to inject malicious code into the username field on the assets/add/ssl-provider-account.php page, leading to a cross-site scripting (XSS) attack. This makes it possible for an attacker to gain access to sensitive information stored on the platform and potentially take over user accounts.

If this vulnerability is exploited, attackers could gain access to sensitive information like personal identifiable information (PII), financial data, SSL keys, email addresses, and passwords. They could also use an XSS payload to upload and execute malicious scripts, causing significant harm to the business or organization. This vulnerability is especially serious as the stored information on the DomainMOD database is sensitive and proprietary, making it attractive to attackers.

In light of this vulnerability, it is essential for companies and organizations to prioritize the security of their digital assets. s4e.io is a platform that can provide regular vulnerability assessments and alerts for vulnerabilities to its users. With its pro features, and by subscribing to the platform, users can identify and neutralize vulnerabilities before attackers can take advantage of them. By being proactive with security measures like these, companies and organizations can minimize the risks of cyber attacks and safeguard their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users should take the following precautions:

  • Update DomainMOD to the latest version, which addresses the vulnerability.
  • Use complex passwords for all user accounts.
  • Regularly monitor system logs for any suspicious activity.
  • Consider employing a web application firewall (WAF) to filter incoming traffic and block attacks.
  • Ensure that all data in transit is protected with encryption to avoid eavesdropping attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.