CVE-2026-36460

Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-03 18:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-36460

Mitre link : CVE-2026-36460

CVE.ORG link : CVE-2026-36460


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')