Medium severity5.3NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026
CVE-2022-44543
CVE-2022-44543
Description
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
in2code/femanagerPackagist | >= 7.0.0, < 7.0.1 | 7.0.1 |
in2code/femanagerPackagist | >= 6.0.0, < 6.3.3 | 6.3.3 |
in2code/femanagerPackagist | < 5.5.2 | 5.5.2 |
Affected products
2- TYPO3/femanager extensiondescription
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-59m9-p6cm-94q5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-44543ghsaADVISORY
- typo3.org/help/security-advisoriesnvdVendor AdvisoryWEB
- typo3.org/security/advisory/typo3-ext-sa-2022-015nvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/in2code/femanager/CVE-2022-44543.yamlghsaWEB
- github.com/in2code-de/femanager/commit/827edbc767b1cb6c0cb77d82e46b88fea3b22ad9ghsaWEB
- github.com/in2code-de/femanager/releases/tag/5.5.2ghsaWEB
- github.com/in2code-de/femanager/releases/tag/6.3.3ghsaWEB
- github.com/in2code-de/femanager/releases/tag/7.0.1ghsaWEB
News mentions
0No linked articles in our index yet.