LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scripting (XSS) vulnerability exists in the LinkAce. This issue occurs in the "URL" field of the "Edit Link" module, where user input is not properly sanitized or encoded before being reflected in the HTML response. This allows attackers to inject and execute arbitrary JavaScript in the context of the victim’s browser, leading to potential session hijacking, data theft, and unauthorized actions. This vulnerability is fixed in 1.15.6.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Dec 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scripting (XSS) vulnerability exists in the LinkAce. This issue occurs in the "URL" field of the "Edit Link" module, where user input is not properly sanitized or encoded before being reflected in the HTML response. This allows attackers to inject and execute arbitrary JavaScript in the context of the victim’s browser, leading to potential session hijacking, data theft, and unauthorized actions. This vulnerability is fixed in 1.15.6. | |
Title | Reflected Cross-Site Scripting (XSS) Vulnerability in LinkAce | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-27T15:50:09.784Z
Updated: 2024-12-27T21:01:15.817Z
Reserved: 2024-12-26T19:28:20.782Z
Link: CVE-2024-56507
Vulnrichment
Updated: 2024-12-27T21:00:15.631Z
NVD
Status : Awaiting Analysis
Published: 2024-12-27T16:15:25.043
Modified: 2024-12-27T21:15:08.287
Link: CVE-2024-56507
Redhat
No data.