CVE-2024-56507

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Dec 27, 2024
CWE ID 79

Summary

CVE-2024-56507 is a reflected cross-site scripting (XSS) vulnerability affecting the LinkAce self-hosted archive software prior to version 1.15.6. The flaw resides in the "URL" field of the "Edit Link" module, where user input is not adequately sanitized or encoded before being reflected in the HTML response. Attackers can exploit this vulnerability by injecting and executing arbitrary JavaScript in the victim's browser. Potential consequences of this vulnerability include session hijacking, data theft, and unauthorized actions. This issue has been rectified in LinkAce version 1.15.6.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share