An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema.
References
| Link | Resource |
|---|---|
| https://desktopalert.net | Product |
| https://desktopalert.net/cve-2025-54561/ | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:46
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Desktopalert pingalert Application Server
Desktopalert |
|
| References | () https://desktopalert.net - Product | |
| References | () https://desktopalert.net/cve-2025-54561/ - Vendor Advisory | |
| CPE | cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:* |
14 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
14 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 18:15
Updated : 2025-11-20 14:46
NVD link : CVE-2025-54561
Mitre link : CVE-2025-54561
CVE.ORG link : CVE-2025-54561
JSON object : View
Products Affected
desktopalert
- pingalert_application_server
CWE
CWE-284
Improper Access Control
