Filtered by vendor Domainmod
Subscriptions
Filtered by product Domainmod
Subscriptions
Total
28 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-1010095 | 1 Domainmod | 1 Domainmod | 2024-08-05 | N/A |
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page. | ||||
CVE-2019-15811 | 1 Domainmod | 1 Domainmod | 2024-08-05 | N/A |
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS. | ||||
CVE-2019-9080 | 1 Domainmod | 1 Domainmod | 2024-08-04 | 7.5 High |
DomainMOD before 4.14.0 uses MD5 without a salt for password storage. | ||||
CVE-2020-35358 | 1 Domainmod | 1 Domainmod | 2024-08-04 | 9.8 Critical |
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality. | ||||
CVE-2020-20988 | 1 Domainmod | 1 Domainmod | 2024-08-04 | 5.4 Medium |
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter. | ||||
CVE-2020-20990 | 1 Domainmod | 1 Domainmod | 2024-08-04 | 5.4 Medium |
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter. | ||||
CVE-2020-20989 | 1 Domainmod | 1 Domainmod | 2024-08-04 | 4.3 Medium |
A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs. | ||||
CVE-2020-12735 | 1 Domainmod | 1 Domainmod | 2024-08-04 | 9.8 Critical |
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover. |