MEDIUM🇵🇱 Wersja polska

CVE-2026-31013

CVSS 6.1v3.1pub. 2026-04-21upd. 2026-04-23

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Dovestones Ad Phonebook

    APP
    Dovestones
    < 4.0.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2015-8267CRITICAL10.0PL ✓same vendor

Nieautoryzowany reset hasła w Dovestones AD Self Password Reset

CVE-2026-31014MEDIUM6.3same vendor

Dovestones Softwares AD Self Update <4.0.0.5 jest podatny na CSRF. Zaatakowany endpoint przetwarzać żądania zm...