CVE-2023-45023 Details
Description
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
A broken access control vulnerability has been identified in the TYPO3 femanager extension, versions 7.0.0 prior to 7.2.2. The vulnerability arises because the invitation component lacks proper permission checks, allowing remote users to create frontend accounts with access to specific groups, depending on the plugin's configuration.
Users are advised to update the femanager extension to version 7.2.2, available through the TYPO3 Extension Manager, Packagist, or the TYPO3 Extensions Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2023-008 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 femanager | >= 7.0.0, <= 7.2.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion