Undefined · Undefined · CVE-2026-36460
**Name of the Vulnerable Software and Affected Versions**
Dovestones Softwares ADPhonebook versions prior to 4.0.1.1
**Description**
An issue exists where an authenticated administrator can store malicious JavaScript payloads in several configuration sections. This occurs because the '/Admin/Save' API endpoint lacks proper input validation and output encoding, leading to Cross Site Scripting (XSS), a technique where malicious scripts are injected into trusted websites.
**Recommendations**
Update to version 4.0.1.1 or later.
Avoid using the '/Admin/Save' API endpoint for configuration changes until the update is applied.