Incorrect Access Control in Femanager Extension for TYPO3 by TYPO3 GmbH
CVE-2023-45023

4.2MEDIUM

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2023-45023?

The Femanager extension for TYPO3 prior to version 7.2.2 exhibits a serious vulnerability due to inadequate permissions checks in its invitation component. This oversight allows unauthorized users to potentially gain access to sensitive functions, compromising the security of the system. Users are encouraged to update to the latest version to mitigate this risk.

Affected Version(s)

femanager 7.0.0 < 7.2.2

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.