We’d love your feedback! Only 3 short questions and 5 min of your time. Take the short survey →

Security Advisories

About Security Advisories

Security advisories are official notifications about vulnerabilities and security-related issues in PingAlert products. They provide details on the problem, its potential impact, and recommendations for mitigation, such as patches or updates.

Security Advisory 2025-10-25

This advisory addresses several vulnerabilities in the Web Application and Desktop Client of affected versions of Desktop Alert (PingAlert). Desktop Alert is not aware of any exploitation of these vulnerabilities.

PingAlert has investigated all reports of security vulnerabilities affecting supported products and services. This security advisory has been issued following the completion of a thorough investigation and a software update has been released to address these vulnerabilities. Installing the recommended update in this advisory will help maintain the security of your Desktop Alert product.

Security BulletinProductCVE IDPublish Date
Arbitrary File Write via Directory TraversalPingAlert Application ServerCVE-2025-543472025-10-25
Backdoor Authentication Logic in Login FunctionalityPingAlert Application ServerCVE-2025-543392025-10-25
Broken AuthenticationPingAlert Application ServerCVE-2025-543432025-10-25
Hard-coded Credentials and Cryptographic KeysPingAlert Application ServerCVE-2025-543412025-10-25
Reflected Cross-site ScriptingPingAlert Application ServerCVE-2025-543462025-10-25
Disclosure of User HashesPingAlert Application ServerCVE-2025-543382025-10-25
Use of Insecure Hashing AlgorithmPingAlert Application ServerCVE-2025-543402025-10-25
Username EnumerationPingAlert Application ServerCVE-2025-545632025-10-25
Stored Cross-site ScriptingPingAlert Application ServeCVE-2025-543482025-10-25
Broken Authorization SchemaPingAlert Application ServerCVE-2025-545612025-10-25
Technical Information Disclosed Through Stack TracePingAlert Application ServerCVE-2025-545622025-10-25
Incorrect Path Resolution For Custom Logo Upload FeaturePingAlert Application ServerCVE-2025-545592025-10-25
Password Stored in Clear TextPingAlert Application ServerCVE-2025-543422025-10-25
Exposure of Credentials via Residual Development Configuration FilePingAlert Application ServerCVE-2025-543452025-10-25
Server-side Request ForgeryPingAlert Application ServerCVE-2025-545602025-10-25