Showing 2 vulnerabilities on this page for GOautodial

Signals CISA KEV Ransomware Nuclei
GOautodial vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaScript in victim browsers.

CWE-79Feb 11, 2026
CVSS5.1v4.0EPSS0.184%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GOautodial 4.0 - Persistent Cross-Site Scripting

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.

CWE-79Jan 29, 2026
CVSS5.1v4.0EPSS0.24%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX