Home

Description

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.

PUBLISHED Reserved 2026-03-09 | Published 2026-04-21 | Updated 2026-04-21 | Assigner mitre

References

dovestones.com/download/

gist.github.com/pentestrox/a35cd5df1a5a84eabada897fc4ffcc79

cve.org (CVE-2026-31013)

nvd.nist.gov (CVE-2026-31013)

Download JSON