Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 03 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dovestones
Dovestones adphonebook |
|
| Vendors & Products |
Dovestones
Dovestones adphonebook |
Wed, 03 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-03T17:18:12.889Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36460
No data.
Status : Received
Published: 2026-06-03T18:16:20.997
Modified: 2026-06-03T18:16:20.997
Link: CVE-2026-36460
No data.
OpenCVE Enrichment
Updated: 2026-06-03T18:30:35Z
Weaknesses
No weakness.