An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.
References
| Link | Resource |
|---|---|
| https://desktopalert.net/cve-2025-54338/ | Vendor Advisory |
Configurations
History
05 Dec 2025, 20:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Desktopalert pingalert Application Server
Desktopalert |
|
| CPE | cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:* | |
| References | () https://desktopalert.net/cve-2025-54338/ - Vendor Advisory |
24 Nov 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 22:15
Updated : 2025-12-05 20:28
NVD link : CVE-2025-54338
Mitre link : CVE-2025-54338
CVE.ORG link : CVE-2025-54338
JSON object : View
Products Affected
desktopalert
- pingalert_application_server
CWE
CWE-284
Improper Access Control
