DomainMOD through version 4.11.01 is vulnerable to cross-site scripting via the /assets/add/category.php CatagoryName and StakeHolder parameters.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view