Metrics
Affected Vendors & Products
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goautodial
Goautodial goautodial |
|
| Vendors & Products |
Goautodial
Goautodial goautodial |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaScript in victim browsers. | |
| Title | GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T15:57:23.145Z
Reserved: 2026-02-11T14:36:32.911Z
Link: CVE-2019-25316
Updated: 2026-02-11T15:57:14.807Z
Status : Awaiting Analysis
Published: 2026-02-11T15:16:10.613
Modified: 2026-02-11T15:27:26.370
Link: CVE-2019-25316
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:37:53Z