CVE-2026-45343 | Kovah LinkAce up to 2.5.5 SSO/OAuth cross site scripting (GHSA-jx4g-ph82-x9mm)
ID: 6fa0b93e-0241-5641-85e1-858fc495c84d
STIX ID: report--6fa0b93e-0241-5641-85e1-858fc495c84d
Feed Name: VulDB Recent Entries
LinkAce versions up to 2.5.5 contain a stored XSS (CVE-2026-45343) in SSO/OAuth where an attacker-controlled OAuth display name plus creating an API token plants a persistent script in the audit log; when an administrator views /system/audit the payload executes, enabling cookie theft, CSRF token exfiltration, or actions the admin can perform. The advisory reports exploitation is easy in principle but no public exploit is available and recommends upgrading to LinkAce 2.5.6 to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
