LinkStackOrg/LinkStack

LinkStackOrg/LinkStack

Releases131
Frequency1 week 4 days
Last Release
Stars3.6K
LinkStack - the ultimate solution for creating a personalized & professional profile page. Showcase all your important links in one place, forget the limitation of one link on social media. Set up your personal site on your own server with just a few clicks.

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM5.5 MEDIUM

A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

3.5 LOW4 MEDIUM

A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet.

9.8 CRITICAL

Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

8.8 HIGH

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.