No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goautodial
Goautodial goautodial |
|
| Vendors & Products |
Goautodial
Goautodial goautodial |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaScript in victim browsers. | |
| Title | GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T15:57:23.145Z
Reserved: 2026-02-11T14:36:32.911Z
Link: CVE-2019-25316
Updated: 2026-02-11T15:57:14.807Z
Status : Awaiting Analysis
Published: 2026-02-11T15:16:10.613
Modified: 2026-02-11T15:27:26.370
Link: CVE-2019-25316
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:37:53Z