Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/friendica/friendica/issues/14220 | issue tracking exploit |
https://friendi.ca/2024/08/17/friendica-2024-08-released/ | release notes |
https://github.com/friendica/friendica/releases/tag/2024.08 | release notes |