File Upload Vulnerability in LinkAce Affects Self-hosted Bookmark Manager
CVE-2024-56508

7.6HIGH

Key Information:

Vendor

Kovah

Status
Vendor
CVE Published:
27 December 2024

What is CVE-2024-56508?

LinkAce, a self-hosted archive platform for collecting links, was found to have a vulnerability in its 'Import Bookmarks' feature prior to version 1.15.6. This issue allows an attacker to upload malicious HTML files that can contain JavaScript payloads. When these links are accessed by users, the embedded scripts can execute, leading to potential reflected or persistent Cross-Site Scripting (XSS) attacks. Users are advised to update to the latest version to mitigate this security risk and protect their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

LinkAce < 1.15.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.