PT-2025-36500 · Linkace · Linkace
Medok228
·
Published
2025-09-08
·
Updated
2025-09-08
·
CVE-2025-53838
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
LinkAce versions prior to 2.1.9
Description:
LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability allows an attacker to inject arbitrary JavaScript, which is then executed in the context of a user's browser when a malicious link is clicked. The application contains a stored XSS vulnerability due to insufficient filtering and escaping of user-supplied data inserted into link attributes. Malicious JavaScript code can be saved in the database along with the link and executed in the user’s browser when clicking the link, leading to arbitrary script execution within the context of the site.
Recommendations:
Update LinkAce to version 2.1.9 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linkace