CVE-2025-62720 affects LinkAce versions 2.3.1 and below, allowing any authenticated user to export the entire database of links, including private links from all users. This vulnerability, rated Medium with a CVSS score of 6.5, stems from a missing access control in the HTML and CSV export functions, leading to a complete compromise of confidentiality (C:H). While no active exploitation, public exploits, or significant community discussion have been observed, the flaw is easily exploitable by any authenticated user over the network with low attack complexity. The issue is resolved in LinkAce version 2.4.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.0CPE matchmatch criteria | cpe:2.3:a:linkace:linkace:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.