CVE-2026-36460

MEDIUM

Dovestones Softwares ADPhonebook < 4.0.1.1 - Authenticated Stored Cross-Site Scripting via Admin Save API

Title source: llm
STIX 2.1

Description

Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.

Scores

CVSS v3 4.8
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Jun 03, 2026
Tracked Since Jun 03, 2026