CVE-2026-36460

Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.
Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Dovestones Softwares ADPhonebook anterior a la v4.0.1.1 es vulnerable a una vulnerabilidad de Cross Site Scripting. La API /Admin/Save permite a un usuario administrador autenticado almacenar cargas útiles de JavaScript maliciosas en múltiples secciones de configuración sin una validación de entrada adecuada ni codificación de salida.

08 Jun 2026, 17:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

03 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 18:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-36460

Mitre link : CVE-2026-36460

CVE.ORG link : CVE-2026-36460


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')