PT-2026-28578 · Linkace · Linkace
Amemoyoi
·
Publicado
2026-03-27
·
Atualizado
2026-03-28
·
CVE-2026-33954
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LinkAce versions prior to 2.5.3
Description
LinkAce is a self-hosted archive for website links. Versions prior to 2.5.3 allow disclosure of a private note attached to a non-private link to another authenticated user through the web interface. The API correctly enforces note visibility, but the web link detail page does not apply equivalent filtering. An authenticated user permitted to view another user’s
internal or public link can read that user’s private notes attached to the link.Recommendations
Update to version 2.5.3 or later.
Exploit
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linkace