LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scripting (XSS) vulnerability exists in the LinkAce. This issue occurs in the "URL" field of the "Edit Link" module, where user input is not properly sanitized or encoded before being reflected in the HTML response. This allows attackers to inject and execute arbitrary JavaScript in the context of the victim’s browser, leading to potential session hijacking, data theft, and unauthorized actions. This vulnerability is fixed in 1.15.6.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linkace
Linkace linkace |
|
CPEs | cpe:2.3:a:linkace:linkace:*:*:*:*:*:*:*:* | |
Vendors & Products |
Linkace
Linkace linkace |
Fri, 27 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Dec 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scripting (XSS) vulnerability exists in the LinkAce. This issue occurs in the "URL" field of the "Edit Link" module, where user input is not properly sanitized or encoded before being reflected in the HTML response. This allows attackers to inject and execute arbitrary JavaScript in the context of the victim’s browser, leading to potential session hijacking, data theft, and unauthorized actions. This vulnerability is fixed in 1.15.6. | |
Title | Reflected Cross-Site Scripting (XSS) Vulnerability in LinkAce | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-27T15:50:09.784Z
Updated: 2024-12-27T21:01:15.817Z
Reserved: 2024-12-26T19:28:20.782Z
Link: CVE-2024-56507

Updated: 2024-12-27T21:00:15.631Z

Status : Analyzed
Published: 2024-12-27T16:15:25.043
Modified: 2025-10-06T15:04:22.130
Link: CVE-2024-56507

No data.