Description
Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23760 | Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function. |
References
| Link | Providers |
|---|---|
| https://github.com/friendica/friendica/issues/13884 |
|
History
Mon, 07 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:friendica:friendica:*:*:*:*:*:*:*:* |
Tue, 18 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-18T19:59:31.250Z
Reserved: 2024-02-19T00:00:00.000Z
Link: CVE-2024-26495
Updated: 2024-08-02T00:07:19.462Z
Status : Analyzed
Published: 2024-04-03T03:15:09.533
Modified: 2025-04-07T14:25:49.647
Link: CVE-2024-26495
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD