Impact
The femanager extension does not verify the dedicated admin confirmation token during an admin-approval request, allowing any user to self‑approve an account that is awaiting administrative approval. This flaw results in an elevation of privileges, enabling an attacker to activate a new account without the necessary administrative consent. The vulnerability is a classic example of incorrect authorization (CWE‑863) and introduces a risk of unauthorized account access.
Affected Systems
TYPO3 users who employ the femanager extension are affected. No specific version numbers are listed; therefore any deployment of femanager that has not been patched against this flaw remains vulnerable. Administrators should check the installed version of the extension.
Risk and Exploitability
With a CVSS score of 8.3, this issue is considered high severity. The EPSS score is not available, but the ease of exploitation is significant: the attacker only needs to trigger the public ‘resend‑confirmation’ action to obtain a confirmation hash and then submit it with an approval request, both accessible to unauthenticated or low‑privilege users. The flaw is listed outside the KEV catalog, but the potential impact warrants immediate remediation.
OpenCVE Enrichment