VYPR

Ad Phonebook

by Dovestones

Source repositories

CVEs (1)

  • CVE-2026-31013MedApr 21, 2026
    risk 0.40cvss 6.1epss 0.00

    Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.