Insecure Direct Object Reference in TYPO3 Femanager Extension
CVE-2025-48202

5.3MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
21 May 2025

What is CVE-2025-48202?

The Femanager extension for TYPO3 prior to version 8.2.1 contains a vulnerability that permits Insecure Direct Object Reference (IDOR). This issue can lead to unauthorized access to sensitive data by manipulating the parameters the application uses to reference objects. Attackers may exploit this flaw to gain access to user resources or perform unauthorized actions, potentially compromising user privacy and application integrity. It is imperative for TYPO3 users to update to the latest version to maintain security and safeguard against such threats.

Affected Version(s)

femanager extension 5.5.0 < 5.5.5

femanager extension 6.0.0 < 6.4.1

femanager extension 7.0.0 < 7.4.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.