216.73.216.36

CVE-2025-54346

· Published 14/11/2025 18:15 · Modified 20/11/2025 14:59

Labels: CVE-2025-54346 2025-11-14CVE-2025-54346CWE-80[email protected]

Essential information

Published
14/11/2025 18:15
Modified
20/11/2025 14:59
Author
Creator
CVSS
7.6 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

CVSS metrics

Description

A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
desktopalert / pingalert application server cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:*

References