CVE-2024-26495: XSS
Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26495?
The severity of CVE-2024-26495 is high due to the potential for remote code execution and sensitive data exposure.
How do I fix CVE-2024-26495?
To fix CVE-2024-26495, upgrade to the latest version of Friendica that is patched for this vulnerability.
What are the risks associated with CVE-2024-26495?
The risks associated with CVE-2024-26495 include the possibility of arbitrary code execution and unauthorized access to sensitive information.
Which versions of Friendica are affected by CVE-2024-26495?
CVE-2024-26495 affects Friendica versions after v.2023.12.
Can CVE-2024-26495 be exploited through user-generated content?
Yes, CVE-2024-26495 can be exploited through user-generated content when BBCode tags are used in post content and comments.