Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4xp5-hr35-84cx | Broken Access Control in extension "femanager" |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2023-010 |
|
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing permission checks allow frontend users to edit or delete arbitrary accounts in TYPO3 femanager |
Mon, 14 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Frontend User Data Modification and Deletion via Access Control Bypass in TYPO3 femanager 7.x |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Frontend User Data Modification and Deletion via Access Control Bypass in TYPO3 femanager 7.x |
Mon, 14 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T14:58:28.781Z
Reserved: 2023-12-10T00:00:00.000Z
Link: CVE-2023-50459
Updated: 2026-09-14T14:58:24.103Z
Status : Received
Published: 2026-09-14T07:17:15.353
Modified: 2026-09-14T15:17:03.600
Link: CVE-2023-50459
No data.
OpenCVE Enrichment
Updated: 2026-09-15T16:15:15Z
Github GHSA