PT-2026-34172 · Kovah · Linkace
Published
2026-04-21
·
Updated
2026-04-27
·
CVE-2026-40905
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LinkAce versions prior to 2.5.4
Description
An issue exists where the application improperly trusts user-controlled HTTP headers. Specifically, the application uses the
X-Forwarded-Host header when generating password reset URLs. An attacker can manipulate this header during a password reset request to inject a malicious domain into the reset link sent via email. If a victim clicks this link, the password reset token is transmitted to the attacker-controlled server, allowing the attacker to capture the token and reset the victim's password, resulting in full account takeover.Recommendations
Update to version 2.5.4.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linkace