CVE-2025-54348

Source
https://cve.org/CVERecord?id=CVE-2025-54348
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54348.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54348
Published
2025-11-14T18:15:49.063Z
Modified
2026-03-13T03:32:27.626579Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54348.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.1.0.11"
            },
            {
                "fixed": "6.1.1.4"
            }
        ]
    }
]