Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor states "the feature still requires a valid authentication cookie even if the route is accessible to non-logged users.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T22:24:59.488Z
Reserved: 2021-04-05T00:00:00
Link: CVE-2021-30141
Updated: 2024-08-03T22:24:59.488Z
Status : Modified
Published: 2021-04-05T23:15:12.190
Modified: 2024-11-21T06:03:23.117
Link: CVE-2021-30141
No data.
OpenCVE Enrichment
No data.
Weaknesses