PT-2024-22015 · Friendica · Friendica

Leo0Liver

·

Published

2024-08-15

·

Updated

2024-08-19

·

CVE-2024-27731

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Friendica version 2023.12
Description The issue allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parameter. This is a Cross Site Scripting issue.
Recommendations For Friendica version 2023.12, consider restricting the file types that can be attached to prevent exploitation until a patch is available. As a temporary workaround, disabling the file attachment feature can help minimize the risk of sensitive information being obtained.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-27731

Affected Products

Friendica