Authorization Flaw in femanager Extension for TYPO3
CVE-2023-50460

5.4MEDIUM

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2023-50460?

A security vulnerability has been identified in the femanager extension for TYPO3 prior to version 7.2.3. This flaw allows authenticated backend users to execute sensitive actions on frontend user accounts, including user logout, confirmation, refusal, and re-sending of user confirmations. This unauthorized access might lead to significant compromises in user management and the overall integrity of the TYPO3 application. It is crucial for TYPO3 administrators to upgrade to the latest version to mitigate these risks.

Affected Version(s)

femanager 7.0.0 < 7.2.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.