PT-2026-45989 · Undefined · Undefined
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dovestones Softwares ADPhonebook versions prior to 4.0.1.1
Description
An issue exists where an authenticated administrator can store malicious JavaScript payloads in several configuration sections. This occurs because the '/Admin/Save' API endpoint lacks proper input validation and output encoding, leading to Cross Site Scripting (XSS), a technique where malicious scripts are injected into trusted websites.
Recommendations
Update to version 4.0.1.1 or later.
Avoid using the '/Admin/Save' API endpoint for configuration changes until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined