PT-2025-35776 · S Link · Slink

G3Xar

·

Published

2025-09-03

·

Updated

2025-09-03

·

CVE-2025-55944

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Slink version 1.4.9
Description Slink version 1.4.9 allows stored cross-site scripting (XSS) through crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. This issue affects both authenticated and unauthenticated users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55944

Affected Products

Slink