Impact
The femanager extension for TYPO3 does not verify permissions when a frontend user accesses the edit user function. An attacker who is logged in as a frontend user can therefore alter the details of other frontend accounts or delete them completely, a classic case of improper authorization (CWE-863).
Affected Systems
TYPO3 installations that run femanager version 7.x before 7.2.3 are vulnerable. The issue applies to any site that allows frontend users to authenticate and access the edit user feature within the extension.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity vulnerability, and the EPSS score of less than 1 % suggests that exploit requires an authenticated frontend session with edit privileges, an attacker must first log in with a user account that carries such rights; no privilege escalation or additional conditions are necessary. The vulnerability is not listed in the CISA KEV catalog, but the lack of permission checks means that any authenticated user with edit rights can readily tamper with other users’ data or remove accounts entirely.
OpenCVE Enrichment
Github GHSA