A reflected cross-site scripting (XSS) vulnerability has been identified in Dovestones Software ADPhonebook versions prior to 4.0.1.1, specifically in the search parameter of the /ADPhonebook?Department=HR endpoint. The vulnerability arises from insufficient input validation and output encoding, permitting attackers to inject and execute arbitrary JavaScript code within a victim's browser session. This affects all versions of the application below the patched release 4.0.1.1. The vulnerability carries a CVSS 3.1 score of 6.1 (Medium severity) with a network-based attack vector requiring no special privileges but necessitating user interaction. The attack has low complexity and could result in limited confidentiality and integrity impacts, though availability is not compromised. The EPSS score of 0.00036 indicates this vulnerability is among the lower-probability candidates for exploitation relative to the broader CVE landscape. Currently, there is no evidence of active exploitation, public exploit code availability, or inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability remains inactive on industry hot lists, and community attention appears minimal. Organizations running ADPhonebook should prioritize upgrading to version 4.0.1.1 or later as a standard patch management practice, though immediate emergency response measures are not warranted based on current threat indicators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.1.1CPE matchmatch criteria | cpe:2.3:a:dovestones:ad_phonebook:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.