PT-2026-4534 · Sourcecodester · Domain Availability Checker

CVE-2025-70458

·

Published

2026-01-23

·

Updated

2026-01-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Domain Availability Checker version 1.0
Description A DOM-based Cross-Site Scripting (XSS) issue exists in the DomainCheckerApp class within the domain/script.js file. The application does not properly handle user-supplied data in the createResultElement method, utilizing the unsafe innerHTML property to display domain search results. This allows for the injection of malicious scripts.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider modifying the createResultElement function to avoid using the innerHTML property for rendering domain search results.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70458
GHSA-CHM7-VGF7-6F9P

Affected Products

Domain Availability Checker