Impact
The femanager invitation controller does not abort processing after redirecting when supplied with invalid or missing input such as a bad hash or a user that does not exist, is disabled, or has been deleted. An unauthenticated attacker can exploit this flaw to set a new password for, and thereby re‑enable, any existing frontend user account. This effectively provides full ownership of that user’s account, allowing access to any personal data that the user has submitted, as well as potential privilege escalation if the account has higher authorisation than normal frontend users.
Affected Systems
The vulnerability affects the TYPO3 extension femanager, but only the 8.x series of that extension. Versions prior to 8.x or newer releases are not impacted, and the flaw is not present in other TYPO3 extensions.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. EPSS information is not available, but the flaw permits a completely unauthenticated, remote attacker to compromise arbitrary frontend accounts by simply crafting a single HTTP request. Although it is not listed in CISA KEV, the impact on confidentiality, integrity, and availability of user data is substantial, and the exploitation path is straightforward, making mitigation a priority.
OpenCVE Enrichment