PT-2024-26507 · Linkstack · Linkstack

Published

2024-11-29

·

Updated

2025-07-03

·

CVE-2024-35451

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LinkStack versions 2.7.9 through 4.7.7
Description The issue is a Server-Side Request Forgery (SSRF) vulnerability. It affects the resourcesviewscomponentsfavicon.blade.php file, allowing it to be linked with SSRF. This vulnerability poses a risk of local network compromise.
Recommendations For versions 2.7.9 through 4.7.7, patch immediately to resolve the SSRF vulnerability. Additionally, check logs for potential exploits and limit public access to the favicon.blade.php file if the patch cannot be applied immediately. As a temporary workaround, consider restricting access to the resourcesviewscomponentsfavicon.blade.php file until a patch is available.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-35451

Affected Products

Linkstack