Junglewise Threat Intelligence

CVE-2026-36460: Dovestones Softwares ADPhonebook stored XSS in Admin Save API

CVE-2026-36460 · Severity: info · CVSS 4.8 · Published 2026-06-03

Executive brief

Dovestones Softwares ADPhonebook, a tool used to manage and display Active Directory contact information, contains a security flaw in its administrative settings. An authorized administrator can save malicious scripts into the application's configuration, which then run automatically when other users view those settings. This could lead to the theft of login sessions, unauthorized access to sensitive directory data, or the redirection of users to malicious websites.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Dovestones Softwares ADPhonebook versions prior to 4.0.1.1. The vulnerability is located in the /Admin/Save API endpoint, which fails to perform adequate input validation or output encoding on several configuration fields, including Search Filter, Domain Mapping, and General Settings. An authenticated attacker with administrative privileges can inject arbitrary JavaScript payloads into these fields. These payloads are stored in the application database and executed in the browser of any user (typically other administrators) who subsequently views the affected configuration pages. This can result in session hijacking, cookie theft, or unauthorized actions performed in the context of the victim's session. The issue is resolved in version 4.0.1.1.

Affected products

  • Dovestones Softwares ADPhonebook before 4.0.1.1

Timeline

  • 2025-11-13: other: Vulnerability discovered by Fedrick R. Sequeira (Accenture)
  • 2026-06-03: disclosed: CVE published to NVD
  • 2026-06-03: patched: Vendor released version 4.0.1.1 to address the issue

References