A
Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
References
| Link | Resource |
|---|---|
| https://desktopalert.net | Product |
| https://desktopalert.net/cve-2025-54348/ | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Desktopalert
Desktopalert pingalert Application Server |
|
| CPE | cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:* | |
| References | () https://desktopalert.net - Product | |
| References | () https://desktopalert.net/cve-2025-54348/ - Vendor Advisory |
14 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-80 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
14 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 18:15
Updated : 2025-11-20 14:54
NVD link : CVE-2025-54348
Mitre link : CVE-2025-54348
CVE.ORG link : CVE-2025-54348
JSON object : View
Products Affected
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)