First published: Thu Feb 02 2023(Updated: )
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
In2code Femanager | <5.5.3 | |
In2code Femanager | >=6.0.0<6.3.4 | |
In2code Femanager | >=7.0.0<7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25014 is considered a high-severity vulnerability due to its potential for unauthorized deletion of frontend users.
To fix CVE-2023-25014, update the femanager extension to version 5.5.3, 6.3.4, or 7.1.0 or later.
CVE-2023-25014 affects all users of the femanager extension below version 5.5.3, 6.3.4, and 7.1.0 for TYPO3.
Exploiting CVE-2023-25014 allows an unauthenticated attacker to delete all frontend users, leading to potential data loss.
The specific component vulnerable in CVE-2023-25014 is the InvitationController of the femanager extension.