Vulnerabilities
Vulnerable Software
Friendica:  >> Friendica  >> 3.4.3  Security Vulnerabilities
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor states "the feature still requires a valid authentication cookie even if the route is accessible to non-logged users.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-04-05


Contact Us

Shodan ® - All rights reserved