First published: Fri Oct 03 2014(Updated: )
The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
In2code Femanager | <=1.0.8 | |
In2code Femanager | =1.0.0 | |
In2code Femanager | =1.0.1 | |
In2code Femanager | =1.0.2 | |
In2code Femanager | =1.0.3 | |
In2code Femanager | =1.0.4 | |
In2code Femanager | =1.0.5 | |
In2code Femanager | =1.0.6 | |
In2code Femanager | =1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6292 is considered a critical vulnerability as it allows remote frontend users to modify or delete records of other users.
To fix CVE-2014-6292, upgrade the femanager extension to version 1.0.9 or later.
CVE-2014-6292 affects all versions of the femanager extension prior to version 1.0.9 for TYPO3.
If exploited, CVE-2014-6292 could allow unauthorized users to access, modify, or delete sensitive user records.
While the best solution is to upgrade the extension, restricting access to frontend features can serve as a temporary workaround for CVE-2014-6292.