Insecure Permissions Vulnerability Allows Remote Attacker to Access Sensitive Information and Execute Arbitrary Code
CVE-2024-27730
9.8CRITICAL
What is CVE-2024-27730?
The Friendica platform, specifically version 2023.12, is impacted by an insecure permissions vulnerability that allows remote attackers to leverage the cid parameter found within the calendar event feature. This flaw can be exploited to access sensitive information and execute arbitrary code, posing significant risks to users and data integrity. Implementing proper access controls and validation mechanisms is critical to mitigate these vulnerabilities and protect user data from exploitation.
