What is CVE-2026-72550?
CVE-2026-72550: An SQL injection vulnerability in Friendica allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. This occurs due to unescaped concatenation into a SHOW COLUMNS query, enabling stacked queries. Immediate update to the latest patched version is recommended.
Azərbaycanca: CVE-2026-72550: Friendica platformasında photo-view order parametri vasitəsilə autentifikasiya olmadan SQL injection zəifliyi aşkarlanıb. Bu, uzaqdan hücum edən şəxslərə SHOW COLUMNS sorğusuna müdaxilə edərək ixtiyari SQL əmrlərini icra etməyə imkan verir. Təcili olaraq ən son sabit versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which platform is affected by CVE-2026-72550?
CVE-2026-72550 affects the Friendica platform.
How can an attacker exploiting CVE-2026-72550 execute arbitrary SQL statements?
An attacker can execute arbitrary SQL statements by interfering with the SHOW COLUMNS query via the photo-view order parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.