CVE-2024-27730 Information

Description

Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.

Reference

https://leo.oliver.nz/posts/2024/05/friendica-cve-disclosures/ https://github.com/friendica/friendica/pull/13927

Share on: