CVE-2023-25013: High severity typo3 femanager vulnerability
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.
Other sources
TYPO3-EXT-SA-2023-001: Broken Access Control in extension "femanager" (femanager)
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25013?
CVE-2023-25013 is considered a critical vulnerability due to the potential for unauthenticated users to gain control over frontend user passwords.
How do I fix CVE-2023-25013?
To fix CVE-2023-25013, update the femanager extension to version 5.5.3 or later, 6.3.4 or later, or 7.1.0 or later.
What versions of femanager are affected by CVE-2023-25013?
Versions of femanager before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 are affected by CVE-2023-25013.
Can CVE-2023-25013 be exploited remotely?
Yes, CVE-2023-25013 can be exploited remotely by an unauthenticated user to set passwords for all frontend users.
What is the impact of CVE-2023-25013?
The impact of CVE-2023-25013 is that it allows unauthorized access to user accounts, potentially compromising user data and account integrity.