PT-2025-45055 · Linkace · Linkace

Published

2025-11-04

·

Updated

2025-11-05

·

CVE-2025-62720

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LinkAce versions prior to 2.4.0
Description LinkAce is a self-hosted archive for website links. Versions 2.3.1 and below permit any authenticated user to export the complete database of links, including private links intended only for their owners. The ExportController class’s HTML and CSV export functions retrieve all links without proper access control checks, bypassing intended visibility restrictions. The vulnerable functions do not apply ownership or visibility filtering.
Recommendations Update to version 2.4.0 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-62720
GHSA-CQXV-6V28-2F2H

Affected Products

Linkace