DomainMOD through version 4.11.01 is vulnerable to cross-site scripting via the /assets/add/ssl-provider.php ssl-provider-name and ssl-provider’s-url parameters.
View the template here CVE-2018-20009.yaml
References:
https://github.com/ARPSyndicate/cvemon