CVE-2024-56507
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2024-56507 is a reflected cross-site scripting (XSS) vulnerability affecting the LinkAce self-hosted archive software prior to version 1.15.6. The flaw resides in the "URL" field of the "Edit Link" module, where user input is not adequately sanitized or encoded before being reflected in the HTML response. Attackers can exploit this vulnerability by injecting and executing arbitrary JavaScript in the victim's browser. Potential consequences of this vulnerability include session hijacking, data theft, and unauthorized actions. This issue has been rectified in LinkAce version 1.15.6.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.