A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
References
| Link | Resource |
|---|---|
| https://desktopalert.net | Product |
| https://desktopalert.net/cve-2025-54348/ | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://desktopalert.net - Product | |
| References | () https://desktopalert.net/cve-2025-54348/ - Vendor Advisory | |
| CPE | cpe:2.3:a:desktopalert:pingalert_application_server:*:*:*:*:*:*:*:* | |
| First Time |
Desktopalert
Desktopalert pingalert Application Server |
14 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-80 |
14 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 18:15
Updated : 2025-11-20 14:54
NVD link : CVE-2025-54348
Mitre link : CVE-2025-54348
CVE.ORG link : CVE-2025-54348
JSON object : View
Products Affected
desktopalert
- pingalert_application_server
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
