Impact
The femanager extension version 7, prior to update 7.2.2, contains an Incorrect Access Control flaw. It fails to verify permission for the invitation component, allowing any user who can reach the component to create, modify, or view invitations without proper authorization. The weakness is classified as CWE-863 and carries a CVSS score of 4.2, indicating moderate severity as it does not enable remote code execution but can compromise data integrity and privacy within the system.
Affected Systems
TYPO3 installations that have the femanager extension of version 7 installed, specifically those using any release before 7.2.2, are affected. The vulnerability is limited to the invitation functionality of this extension and does not impact other TYPO3 core features unless they depend on femanager invitations.
Risk and Exploitability
The CVSS score of 4.2 points to a low-to-moderate risk profile. EPSS score is below 1%, and the issue is not listed in CISA’s KEV, it is inferred that exploitation would involve authenticated HTTP requests targeting the invitation endpoint, and the missing permission check lifts the normal authorization barrier. The overall threat level remains moderate, primarily driven by whether the vulnerable extension is present and accessible in a production environment.
OpenCVE Enrichment
Github GHSA