CVE-2026-31013
EUVD-2026-2413221.04.2026, 15:16
Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.
Awaiting analysis
This vulnerability is currently awaiting analysis.