TYPO3 extension femanager Broken Access Control vulnerability
Moderate severity
GitHub Reviewed
Published
Oct 4, 2023
to the GitHub Advisory Database
•
Updated Oct 4, 2023
Description
Published to the GitHub Advisory Database
Oct 4, 2023
Reviewed
Oct 4, 2023
Last updated
Oct 4, 2023
femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.
References