Arbitrary Code Execution and Sensitive Information Theft via SSRF Vulnerability in Friendica
CVE-2024-25864
9.1CRITICAL
What is CVE-2024-25864?
A Server Side Request Forgery (SSRF) vulnerability exists in Friendica versions beyond v.2023.12. This flaw enables a remote attacker to execute arbitrary code and access sensitive information through the fpostit.php component, potentially compromising the security and integrity of affected systems.
