Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf9x-3p57-vp26

Опубликовано: 08 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.

EPSS

Процентиль: 12%
0.0004
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-449

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be malicious. This UI misrepresentation enables attackers to deceive users by displaying trusted previews for harmful links, facilitating phishing attacks and user confusion.

EPSS

Процентиль: 12%
0.0004
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-449