Impact
Linkstack versions 4.8.4 and earlier contain a path traversal flaw that allows an authenticated administrator to supply a crafted file path and read arbitrary files on the host server. The vulnerability directly undermines confidentiality by permitting access to sensitive system or application files such as configuration data, credentials, or other privileged information. The impact is limited to accounts with administrative privileges within the application interface.
Affected Systems
The affected product is Linkstack, specifically all releases up to and including version 4.8.4.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability that the flaw is actively exploited. It is not listed in CISA's KEV catalog, further suggesting limited known exploitation. The CVSS score of 4.9 reflects moderate severity, but the overall risk remains low under current exploitation statistics, especially when administrative accounts are tightly controlled or network access to the vulnerable interface is restricted.
OpenCVE Enrichment