VDB
Sign up
MEDIUM

GHSA-93j4-v838-8767

TYPO3 extension femanager Broken Access Control vulnerability

Quick fix

GHSA-93j4-v838-8767 — in2code/femanager: upgrade to the fixed version with the command below.

composer require in2code/femanager:^7.2.2

Details

femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/in2code/femanager
Introduced in: 7.0.0Fixed in: 7.2.2
Fixcomposer require in2code/femanager:^7.2.2

References