Description
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0614 | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users. |
Github GHSA |
GHSA-3p9x-xxx6-2w4p | Broken Access Control in 3rd party TYPO3 extension "femanager" |
References
History
Wed, 26 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-26T17:37:06.843Z
Reserved: 2023-02-01T00:00:00.000Z
Link: CVE-2023-25014
Updated: 2024-08-02T11:11:43.489Z
Status : Modified
Published: 2023-02-02T01:15:08.670
Modified: 2025-03-26T18:15:23.490
Link: CVE-2023-25014
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA