PT-2026-7610 · Unknown · Goautodial

·

CVE-2019-25316

·

Published

2026-02-11

·

Updated

2026-02-11

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GOautodial version 4.0
Description GOautodial version 4.0 has a persistent cross-site scripting issue. Authenticated attackers can inject malicious scripts through the event title parameter. The issue is exploitable via crafted POST requests with XSS payloads sent to the /CreateEvent.php endpoint, allowing for the execution of arbitrary JavaScript in victim browsers.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the event title parameter before processing it in the CreateEvent.php endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25316

Affected Products

Goautodial