File Upload Vulnerability in LinkAce Affects Self-hosted Bookmark Manager
CVE-2024-56508
7.6HIGH
What is CVE-2024-56508?
LinkAce, a self-hosted archive platform for collecting links, was found to have a vulnerability in its 'Import Bookmarks' feature prior to version 1.15.6. This issue allows an attacker to upload malicious HTML files that can contain JavaScript payloads. When these links are accessed by users, the embedded scripts can execute, leading to potential reflected or persistent Cross-Site Scripting (XSS) attacks. Users are advised to update to the latest version to mitigate this security risk and protect their data.
Affected Version(s)
LinkAce < 1.15.6
