Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-31013

21
FAUCET Score

A reflected cross-site scripting (XSS) vulnerability has been identified in Dovestones Software ADPhonebook versions prior to 4.0.1.1, specifically in the search parameter of the /ADPhonebook?Department=HR endpoint. The vulnerability arises from insufficient input validation and output encoding, permitting attackers to inject and execute arbitrary JavaScript code within a victim's browser session. This affects all versions of the application below the patched release 4.0.1.1. The vulnerability carries a CVSS 3.1 score of 6.1 (Medium severity) with a network-based attack vector requiring no special privileges but necessitating user interaction. The attack has low complexity and could result in limited confidentiality and integrity impacts, though availability is not compromised. The EPSS score of 0.00036 indicates this vulnerability is among the lower-probability candidates for exploitation relative to the broader CVE landscape. Currently, there is no evidence of active exploitation, public exploit code availability, or inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability remains inactive on industry hot lists, and community attention appears minimal. Organizations running ADPhonebook should prioritize upgrading to version 4.0.1.1 or later as a standard patch management practice, though immediate emergency response measures are not warranted based on current threat indicators.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.0.1.1CPE matchmatch criteria
cpe:2.3:a:dovestones:ad_phonebook:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 9th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

dovestones.com / download
Product
gist.github.com / pentestrox/a35cd5df1a5a84eabada897fc4ffcc79
Third Party Advisory