A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.
https://desktopalert.net/cve-2025-54346/
https://desktopalert.net
Source: Mitre, NVD
Published: 2025-11-14
Updated: 2025-11-20
Base Score: 8
Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:C
Severity: High
Base Score: 7.6
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
EPSS: 0.00042