Junglewise Threat Intelligence

CVE-2026-72550: Friendica SQL injection in photo-view order parameter

CVE-2026-72550 · Severity: critical · CVSS 9.8 · Published 2026-08-11

Executive brief

Friendica is a distributed social network platform. An unauthenticated attacker can exploit an unescaped SQL parameter to inject arbitrary database commands, potentially reading, modifying, or deleting the entire database without any credentials or authentication.

Technical details

This is an SQL injection vulnerability in Friendica's photo-view functionality, where the order parameter is concatenated directly into a SHOW COLUMNS query without proper escaping and passed to a bare PDO::query() call. The vulnerability enables stacked statement injection, allowing an attacker to execute arbitrary SQL statements. The attack vector is network-based and requires no authentication or user interaction; an unauthenticated remote attacker can read, modify, or delete data from the entire database. A patch should escape user input or use parameterized queries.

Affected products

  • Friendica Friendica through 2026.08-dev

Timeline

  • 2026-08-11: disclosed

References

Related threats