Description

Multiple cross-site scripting (XSS) vulnerabilities exist in Maian Links. User-supplied data is reflected in HTML pages without proper encoding.

Impact

Attackers can inject malicious scripts that execute when other users browse the links directory, enabling session hijacking and credential theft.

Solution

Upgrade to the latest version of Maian Links.

References