CVE-2024-48622: Domainmod
Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.
Affected products
- Domainmod Domainmod: before 4.12.0 (fixed in 4.12.0)
Published 2024-10-15. Last modified 2026-06-17.