VYPR

Packagist (Composer) package

in2code/femanager

pkg:composer/in2code/femanager

Vulnerabilities (9)

  • CVE-2023-50459MedSep 14, 2026
    affected >= 7.0.0, < 7.2.3fixed 7.2.3

    An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.

  • CVE-2023-45023MedSep 14, 2026
    affected >= 7.0.0, < 7.2.2fixed 7.2.2

    The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

  • CVE-2025-7900MedJul 22, 2025
    affected < 6.4.2fixed 6.4.2

    The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0

  • CVE-2025-48202MedMay 21, 2025
    affected >= 8.0.0, < 8.2.2fixed 8.2.2

    The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.

  • CVE-2022-44543MedDec 12, 2023
    affected >= 7.0.0, < 7.0.1fixed 7.0.1

    The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.

  • CVE-2023-25014HigFeb 2, 2023
    affected < 5.5.3fixed 5.5.3

    An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.

  • CVE-2023-25013HigFeb 2, 2023
    affected < 5.5.3fixed 5.5.3

    An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.

  • CVE-2021-36787MedAug 13, 2021
    affected < 5.5.1fixed 5.5.1

    The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.

  • CVE-2014-6292Oct 3, 2014
    affected < 1.0.9fixed 1.0.9

    The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.