Access Control Vulnerability in TYPO3 femanager Extension by TYPO3
CVE-2023-50459

5.4MEDIUM

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2023-50459?

A critical vulnerability in the femanager extension for TYPO3 allows authenticated frontend users to manipulate data belonging to other users. This flaw arises from improper access permission checks, enabling a user to either alter frontend user data or delete user accounts. Versions prior to 7.2.3 are particularly susceptible to this exploit, making timely updates crucial for safeguarding user information.

Affected Version(s)

femanager 7.0.0 < 7.2.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.