A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.
References
| Link | Resource |
|---|---|
| https://desktopalert.net | Product |
| https://desktopalert.net/cve-2025-54560/ | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://desktopalert.net - Product | |
| References | () https://desktopalert.net/cve-2025-54560/ - Vendor Advisory | |
| First Time |
Desktopalert pingalert Application Server
Desktopalert |
|
| CPE | cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:* |
14 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-918 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.8 |
14 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 18:15
Updated : 2025-11-20 14:48
NVD link : CVE-2025-54560
Mitre link : CVE-2025-54560
CVE.ORG link : CVE-2025-54560
JSON object : View
Products Affected
desktopalert
- pingalert_application_server
CWE
CWE-918
Server-Side Request Forgery (SSRF)
