CVE-2024-39094: XSS
Published Aug 20, 2024
·Updated
Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.
Affected Software
1 affected component
Friendica Friendica=2024.03
Event History
Aug 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39094?
CVE-2024-39094 has a moderate severity level due to its potential for exploitation by malicious users.
2
How do I fix CVE-2024-39094?
To fix CVE-2024-39094, you should update Friendica to version 2024.08 or later.
3
What are the affected components in CVE-2024-39094?
CVE-2024-39094 affects the settings/profile component of Friendica 2024.03.
4
Is CVE-2024-39094 a Cross Site Scripting vulnerability?
Yes, CVE-2024-39094 is identified as a Cross Site Scripting (XSS) vulnerability.
5
What parameters are involved in CVE-2024-39094?
The parameters involved in CVE-2024-39094 include homepage, xmpp, and matrix.