User Export Module Vulnerability in Friendica by Friendica
CVE-2021-30141

7.5HIGH

Key Information:

Vendor

Friendica

Status
Vendor
CVE Published:
5 April 2021

What is CVE-2021-30141?

The User Export module in Friendica version 2021.01 is susceptible to an access control vulnerability that can be exploited by unauthorized users. This flaw allows anonymous users to access the settings/userexport functionality, which should ideally require authentication. The exploited route may lead to significant memory consumption and failed attempts to access data structures, ultimately threatening data security and service performance. Despite the vendor's assurance that a valid authentication cookie is still needed, the potential for misuse remains a critical concern.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.