PT-2024-36823 · Linkace · Linkace
Kwangyun
·
Published
2024-12-27
·
Updated
2025-10-06
·
CVE-2024-56508
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LinkAce versions prior to 1.15.6
Description
The issue occurs in the "Import Bookmarks" functionality, where malicious HTML files can be uploaded containing JavaScript payloads. These payloads execute when the uploaded links are accessed, leading to potential reflected or persistent XSS scenarios.
Recommendations
For versions prior to 1.15.6, update to version 1.15.6 to resolve the issue. As a temporary workaround, consider disabling the "Import Bookmarks" functionality until a patch is available. Restrict access to uploaded links to minimize the risk of exploitation. Avoid using the "Import Bookmarks" feature with untrusted files until the issue is resolved.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linkace