CVE-2021-30141
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor states "the feature still requires a valid authentication cookie even if the route is accessible to non-logged users.
** EN DISPUTA ** El archivo Module/Settings/UserExport.php en Friendica versiones hasta 2021.01, permite que settings/userexport sea usado por usuarios anónimos, como es demostrado por un intento de acceso a un desplazamiento de matriz en un valor de tipo null, y un consumo excesivo de la memoria. NOTA: el proveedor afirma que "la funcionalidad aún requiere una cookie de autenticación válida incluso si la ruta es accesible para usuarios no registrados"
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2021-04-05 CVE Reserved
- 2021-04-05 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-401: Missing Release of Memory after Effective Lifetime
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/friendica/friendica/issues/10110 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/friendica/friendica/pull/10113/commits/acbcc56754121ba080eac5b6fdf69e64ed7fe453 | 2024-06-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Friendica Search vendor "Friendica" | Friendica Search vendor "Friendica" for product "Friendica" | <= 2021.01 Search vendor "Friendica" for product "Friendica" and version " <= 2021.01" | - |
Affected
|