Impact
An authenticated backend user in a TYPO3 installation can use the femanager extension to perform userLogout, confirmUser, refuseUser, and resendUserConfirmation actions on any frontend user regardless of that user’s permissions. The flaw is an authorization bypass, exposed as CWE‑863, and allows the attacker to terminate sessions, reset confirmation status, or deny account access, but does not provide code execution or privilege escalation beyond the existing backend role.
Affected Systems
TYPO3 femanager extension versions 7.x prior to 7.2.3 are affected. Any TYPO3 site that has installed a femanager extension in those releases is vulnerable unless it has been upgraded.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. Exploitation requires authenticated access to a backend account, limiting the threat to environments where an attacker can obtain legitimate backend credentials. The EPSS score is less than 1%, showing a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Overall, the risk remains moderate, driven mainly by the need for backend access.
OpenCVE Enrichment