DomainMOD through version 4.11.01 is vulnerable to cross-site scripting via the /assets/add/ssl-provider.php ssl-provider-name and ssl-provider's-url parameters.
id: CVE-2018-20009
info:
name: DomainMOD 4.11.01 - Cross-Site Scripting
author: arafatansari
...