Impact
The femanager extension does not properly restrict which frontend usergroups a logged‑in user may assign to their own account when the profile edit plugin uses default configuration. This oversight enables a user to add themselves to any frontend group, giving them privileges that were not intended for them. The flaw is a classic access‑control violation and can lead to unauthorized access to group‑protected content or functionalities. The weakness is categorized as CWE‑862.
Affected Systems
The vulnerability affects the TYPO3 femanager extension. No specific version ranges are listed, so all installed releases of femanager that have not been patched should be considered potentially vulnerable. Affected sites are those that use the default profile edit configuration permitted for group assignment.
Risk and Exploitability
The CVSS score for this issue is 6, indicating a medium severity. EPSS information is not available, so the exact likelihood of exploitation cannot be quantified. The issue is not listed in CISA’s KEV catalog. The likely attack vector is through the web interface: a logged‑in user submits a profile edit request that includes additional group identifiers, which the extension blindly accepts. No special privileges or network-level access are required beyond normal user authentication.
OpenCVE Enrichment