diff --git a/cves/2018/CVE-2018-19137.yaml b/cves/2018/CVE-2018-19137.yaml index 34290c7d35..f53198060c 100644 --- a/cves/2018/CVE-2018-19137.yaml +++ b/cves/2018/CVE-2018-19137.yaml @@ -9,8 +9,13 @@ info: reference: - https://github.com/domainmod/domainmod/issues/79 - https://nvd.nist.gov/vuln/detail/CVE-2018-19137 + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N + cvss-score: 6.1 + cve-id: CVE-2018-19137 + cwe-id: CWE-79 metadata: - verified: true + verified: "true" tags: cve,cve2018,domainmod,xss,authenticated requests: diff --git a/cves/2018/CVE-2018-19892.yaml b/cves/2018/CVE-2018-19892.yaml index e0e990417d..81ee180a25 100644 --- a/cves/2018/CVE-2018-19892.yaml +++ b/cves/2018/CVE-2018-19892.yaml @@ -8,8 +8,14 @@ info: DomainMOD 4.11.01 is vulnerable to Cross Site Scripting (XSS) via /domain//admin/dw/add-server.php DisplayName parameters. reference: - https://www.exploit-db.com/exploits/45959 + - https://github.com/domainmod/domainmod/issues/85 + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N + cvss-score: 4.8 + cve-id: CVE-2018-19892 + cwe-id: CWE-79 metadata: - verified: true + verified: "true" tags: cve,cve2018,domainmod,xss,authenticated requests: