Impact
The femanager extension for TYPO3 does not verify that the requested user record matches the configured or logged‑in target. An attacker with access to the Detail or List plugin can supply any user ID to retrieve that user's name, email, date of birth, and address. The vulnerability allows confidential personal data to be disclosed to unauthenticated or low‑privileged visitors, constituting a high‑severity information‑exposure flaw (CWE‑639).
Affected Systems
Any installation of the femanager extension for TYPO3 is potentially affected. No specific version numbers are listed in the advisory, so the issue likely applies to all current releases until a patch is released.
Risk and Exploitability
The CVSS score of 8.2 indicates a high impact with no authentication required and a network attack vector. Because the vulnerability can be triggered by anyone who can reach the Detail or List plugin, it is easily exploitable in a typical web environment. No EPSS score is available, and the flaw is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment