Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goautodial goautodial Api
|
|
| CPEs | cpe:2.3:a:goautodial:goautodial:4.0:*:*:*:*:*:*:* cpe:2.3:a:goautodial:goautodial_api:2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Goautodial goautodial Api
|
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goautodial
Goautodial goautodial |
|
| Vendors & Products |
Goautodial
Goautodial goautodial |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaScript in victim browsers. | |
| Title | GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T01:26:04.836Z
Reserved: 2026-02-11T14:36:32.911Z
Link: CVE-2019-25316
Updated: 2026-02-11T15:57:14.807Z
Status : Awaiting Analysis
Published: 2026-02-11T15:16:10.613
Modified: 2026-02-11T15:27:26.370
Link: CVE-2019-25316
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:37:53Z