CVE-2025-59424
LinkAce Vulnerable to Stored XSS on the Audit Page
- Published
- Sep 18, 2025
- Updated
- Sep 18, 2025
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 9, 2026
LinkAce Vulnerable to Stored XSS on the Audit Page
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:NLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The application fails to properly sanitize the username field before it is rendered in the audit log. An authenticated attacker can set a malicious JavaScript payload as their username. When an action performed by this user is recorded (e.g., generate or revoke an API token), the payload is stored in the database. The script is then executed in the browser of any user, particularly administrators, who views the /system/audit page. This vulnerability is fixed in 2.3.1.
LinkAce Stored Cross-Site Scripting (XSS) on the /system/audit page
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.