Description
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
Published: 2026-09-14
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to the invitation component
Action: Patch or Disable
AI Analysis

Impact

The femanager extension version 7, prior to update 7.2.2, contains an Incorrect Access Control flaw. It fails to verify permission for the invitation component, allowing any user who can reach the component to create, modify, or view invitations without proper authorization. The weakness is classified as CWE-863 and carries a CVSS score of 4.2, indicating moderate severity as it does not enable remote code execution but can compromise data integrity and privacy within the system.

Affected Systems

TYPO3 installations that have the femanager extension of version 7 installed, specifically those using any release before 7.2.2, are affected. The vulnerability is limited to the invitation functionality of this extension and does not impact other TYPO3 core features unless they depend on femanager invitations.

Risk and Exploitability

The CVSS score of 4.2 points to a low-to-moderate risk profile. EPSS score is below 1%, and the issue is not listed in CISA’s KEV, it is inferred that exploitation would involve authenticated HTTP requests targeting the invitation endpoint, and the missing permission check lifts the normal authorization barrier. The overall threat level remains moderate, primarily driven by whether the vulnerable extension is present and accessible in a production environment.

Generated by OpenCVE AI on September 15, 2026 at 16:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade femanager to version 7.2.2 or later to restore permission checks for the invitation component.
  • If an immediate upgrade is not feasible, disable the invitation feature or uninstall the femanager extension until the fix is applied.
  • Restrict TYPO3 backend access to trusted users and monitor logs for unusual invitation activity.

Generated by OpenCVE AI on September 15, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-93j4-v838-8767 TYPO3 extension femanager Broken Access Control vulnerability
History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in TYPO3 femanager Invitation Feature

Mon, 14 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in TYPO3 femanager Invitation Feature

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:13:01.462Z

Reserved: 2023-10-03T00:00:00.000Z

Link: CVE-2023-45023

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:31.723Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T06:16:54.207

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-45023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses