Record summary

CVE-2020-37018 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBGOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)ExploitDB exploitby BalzabuNot analyzed1 file
ExploitDB

PoC details

References

4