Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2020-20989

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.
Attacker Value
Unknown

CVE-2020-20990

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.
Attacker Value
Unknown

CVE-2020-20988

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.
Attacker Value
Unknown

CVE-2020-12735

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.