User Export Module Vulnerability in Friendica by Friendica
CVE-2021-30141
7.5HIGH
What is CVE-2021-30141?
The User Export module in Friendica version 2021.01 is susceptible to an access control vulnerability that can be exploited by unauthorized users. This flaw allows anonymous users to access the settings/userexport functionality, which should ideally require authentication. The exploited route may lead to significant memory consumption and failed attempts to access data structures, ultimately threatening data security and service performance. Despite the vendor's assurance that a valid authentication cookie is still needed, the potential for misuse remains a critical concern.
