Insecure Permissions Vulnerability Allows Remote Attacker to Access Sensitive Information and Execute Arbitrary Code
CVE-2024-27730

9.8CRITICAL

Key Information:

Vendor

Friendica

Status
Vendor
CVE Published:
15 August 2024

What is CVE-2024-27730?

The Friendica platform, specifically version 2023.12, is impacted by an insecure permissions vulnerability that allows remote attackers to leverage the cid parameter found within the calendar event feature. This flaw can be exploited to access sensitive information and execute arbitrary code, posing significant risks to users and data integrity. Implementing proper access controls and validation mechanisms is critical to mitigate these vulnerabilities and protect user data from exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.