CVE-2026-36460 Details
Description
Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.
A stored cross-site scripting vulnerability has been identified in Dovestones Software ADPhonebook versions prior to 4.0.1.1. The issue arises in the administrative configuration functionality, where authenticated admin users can inject malicious JavaScript payloads into various application configuration fields. This injection occurs through the '/Admin/Save' API, which lacks adequate input validation and output encoding. Once injected, the payloads are executed when the affected configuration data is viewed, potentially leading to session hijacking or impersonation of administrative accounts.
Users are advised to upgrade to Dovestones Software ADPhonebook version 4.0.1.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 3, 2026CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://dovestones.com/download/ | [email protected] | ProductVendor |
| https://gist.github.com/pentestrox/16d92f8f8114ad3b34805c449f573cef | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Dovestones Software ADPhonebook | <= 4.0.0.11 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |
Volerion