GOautodial Persistent Cross-Site Scripting Vulnerability

Vulnerability

A persistent cross-site scripting vulnerability has been identified in GOautodial version 4.0. This vulnerability allows authenticated agents to inject malicious scripts into message subjects. When an administrator reads these messages, the embedded JavaScript executes, potentially leading to session cookie theft or other client-side attacks.

Impact

Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed when the message is read by an administrator.

Reproduction

To reproduce this vulnerability, log in as an agent and send a message to the user 'goadmin' with a subject that includes a script tag, such as one that alerts document cookies. Once the message is sent, wait for 'goadmin' to read it, which will trigger the execution of the injected script.

Added: Jan 29, 2026, 3:27 PM
Updated: Jan 29, 2026, 4:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.4
exploitability
6.3
remediation
0.0
relevance
2.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.