MEDIUM
GHSA-93j4-v838-8767
TYPO3 extension femanager Broken Access Control vulnerability
Quick fix
GHSA-93j4-v838-8767 — in2code/femanager: upgrade to the fixed version with the command below.
composer require in2code/femanager:^7.2.2Details
femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/in2code/femanager
Introduced in:
7.0.0Fixed in: 7.2.2Fix
composer require in2code/femanager:^7.2.2References
- https://github.com/in2code-de/femanager/commit/cc5f2893613a6b3fd2677c457574ab587a0862ca[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/in2code/femanager/CVE-2023-45023.yaml[WEB]
- https://github.com/in2code-de/femanager[PACKAGE]
- https://github.com/in2code-de/femanager/releases/tag/7.2.2[WEB]
- https://typo3.org/security/advisory/typo3-ext-sa-2023-008[WEB]