Cross-site Scripting Vulnerability in Inlinkz EZ InLinkz Linkup Plugin
CVE-2025-27329
6.5MEDIUM
Key Information:
- Vendor
- Inlinkz
- Status
- Ez Inlinkz Linkup
- Vendor
- CVE Published:
- 24 February 2025
Summary
The Inlinkz EZ InLinkz linkup plugin is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of user input during web page generation. This flaw allows attackers to inject malicious scripts into the web application, potentially affecting clients and users interacting with the compromised application. This vulnerability impacts versions from n/a to 0.18, emphasizing the necessity for updates and proper input validation to safeguard against such attacks.
Affected Version(s)
EZ InLinkz linkup <= 0.18
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
theviper17 (Patchstack Alliance)