CVE-2024-25864: Friendica
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.
Affected products
- Friendica Friendica: from 2023.12
Published 2024-04-03. Last modified 2026-06-17.