---
id: CVE-2020-37018
title: >-
  GOautodial 4.0 contains a persistent cross-site scripting vulnerability that
  allows authenticated agents to inject malicious scripts through message
  subjects
summary: >-
  GOautodial 4.0 contains a persistent cross-site scripting vulnerability that
  allows authenticated agents to inject malicious scripts through message
  subjects. Attackers can craft messages with embedded JavaScript that will
  execute when a…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-01-29'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37018'
references:
  - url: 'https://goautodial.org/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/48690'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/goautodial-persistent-cross-site-scripting
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00273
epssPercentile: 0.17975
ingestedAt: '2026-10-07T08:20:03.892Z'
---

## Overview

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
