CVE-2023-50459
Received Received - Intake

Authentication Bypass in Femanager TYPO3 Extension

Vulnerability report for CVE-2023-50459, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
typo3 femanager to 7.2.2 (inc)
typo3 femanager 7.2.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the femanager extension for TYPO3, versions 7.0.0 to 7.2.2. It involves broken access control, allowing authenticated frontend users to edit or delete other users' data without proper permission checks. Backend users can also perform unauthorized actions like logging out or resending confirmations for any frontend user.

Detection Guidance

Check the installed version of the femanager extension in your TYPO3 system. If it is between 7.0.0 and 7.2.2, the system is vulnerable. Use the TYPO3 Install Tool or backend module to verify the extension version.

Impact Analysis

An attacker with access could modify or delete user accounts, leading to data loss or unauthorized changes. This could disrupt services, compromise user data integrity, and allow further attacks through account manipulation.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of user data, violating GDPR's data integrity and confidentiality requirements. For HIPAA, it may compromise protected health information integrity if user accounts are altered or deleted improperly.

Mitigation Strategies

Update the femanager extension to version 7.2.3 or later immediately. Follow the TYPO3 Security Guide and subscribe to the typo3-announce mailing list for further security updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-50459. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart