First published: Wed Jan 25 2023(Updated: )
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/in2code/femanager | >=7.0.0<7.1.0>=6.0.0<6.3.4<5.5.3 | |
In2code Femanager | <5.5.3 | |
In2code Femanager | >=6.0.0<6.3.4 | |
In2code Femanager | >=7.0.0<7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25013 is considered a critical vulnerability due to the potential for unauthenticated users to gain control over frontend user passwords.
To fix CVE-2023-25013, update the femanager extension to version 5.5.3 or later, 6.3.4 or later, or 7.1.0 or later.
Versions of femanager before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 are affected by CVE-2023-25013.
Yes, CVE-2023-25013 can be exploited remotely by an unauthenticated user to set passwords for all frontend users.
The impact of CVE-2023-25013 is that it allows unauthorized access to user accounts, potentially compromising user data and account integrity.