Skip to content

Instantly share code, notes, and snippets.

CVE-2025-65819 — Unauthorized Configuration Modification in Dovestones AD Phonebook

Summary

Dovestones Software AD Phonebook versions prior to 4.0.0.11 contain an access control flaw in an administrative configuration endpoint that allows unauthenticated attackers to modify application settings despite an HTTP 401 response.


Vulnerability Details

CVE-2025-65818 — Unauthenticated File Upload in Dovestones AD Phonebook

Summary

An authentication and authorization bypass vulnerability exists in Dovestones Software AD Phonebook versions prior to 4.0.0.11. The application exposes an administrative file upload endpoint that can be accessed by unauthenticated remote attackers.


Vulnerability Details