We’d love your feedback! Only 3 short questions and 5 min of your time. Take the short survey →

Security Advisories: CVE-2025-54559

An issue was found in the Application Server of Desktop Alert version 6.1.0.11 to 6.1.1.4 which allows remote Path Traversal for loading arbitrary external content.

Vulnerability Type(CWE-22) Path Traversal
CVE IdentifierCVE-2025-54559
CVSS Score3.7
CVSS Vector(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
VendorDesktop Alert
Affected ProductPingAlert Application Server
Affected Versions6.1.0.11 – 6.1.1.4
AttackerAny authenticated user with Administrative role
ImpactIt allows remote Path Traversal for loading arbitrary external content.
MitigationFixed in version 6.1.1.5

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.