A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
References
| Link | Resource |
|---|---|
| https://desktopalert.net | Product |
| https://desktopalert.net/cve-2025-54346/ | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Desktopalert pingalert Application Server
Desktopalert |
|
| References | () https://desktopalert.net - Product | |
| References | () https://desktopalert.net/cve-2025-54346/ - Vendor Advisory | |
| CPE | cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:* |
14 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.6 |
| CWE | CWE-80 |
14 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 18:15
Updated : 2025-11-20 14:59
NVD link : CVE-2025-54346
Mitre link : CVE-2025-54346
CVE.ORG link : CVE-2025-54346
JSON object : View
Products Affected
desktopalert
- pingalert_application_server
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
