Security Advisory

CVE-2025-70458

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-23 00:00:00
Last updated 2026-01-26 15:40:53
Assigner mitre
State PUBLISHED

Description

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.