Friendica · Friendica · CVE-2024-26495
**Name of the Vulnerable Software and Affected Versions**
Friendica versions after v.2023.12
**Description**
The issue allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function. This is a Cross Site Scripting (XSS) vulnerability.
**Recommendations**
For Friendica versions after v.2023.12, update to a version that includes a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.