An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4xp5-hr35-84cx | Broken Access Control in extension "femanager" |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2023-010 |
|
History
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Frontend User Data Modification and Deletion via Access Control Bypass in TYPO3 femanager 7.x |
Mon, 14 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T06:03:19.959Z
Reserved: 2023-12-10T00:00:00.000Z
Link: CVE-2023-50459
No data.
Status : Received
Published: 2026-09-14T07:17:15.353
Modified: 2026-09-14T07:17:15.353
Link: CVE-2023-50459
No data.
OpenCVE Enrichment
Updated: 2026-09-14T12:45:06Z
Weaknesses
Github GHSA