Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-31013 1 Dovestones 1 Adphonebook 2026-04-22 6.1 Medium
Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.