Executive brief
Friendica is a distributed social network platform. An unauthenticated attacker can exploit an unescaped SQL parameter to inject arbitrary database commands, potentially reading, modifying, or deleting the entire database without any credentials or authentication.
Technical details
This is an SQL injection vulnerability in Friendica's photo-view functionality, where the order parameter is concatenated directly into a SHOW COLUMNS query without proper escaping and passed to a bare PDO::query() call. The vulnerability enables stacked statement injection, allowing an attacker to execute arbitrary SQL statements. The attack vector is network-based and requires no authentication or user interaction; an unauthenticated remote attacker can read, modify, or delete data from the entire database. A patch should escape user input or use parameterized queries.
Affected products
- Friendica Friendica through 2026.08-dev
Timeline
- 2026-08-11: disclosed