CVE-2023-50460: Medium severity Typo3 femanager extension vulnerability
Published Sep 14, 2026
·Updated
An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.
Affected Software
1 affected component
Typo3 femanager extension>=7.0.0<7.2.3
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated TYPO3 backend user can exploit it. No additional user interaction is required.
2
Which frontend-user actions can an affected backend user perform?
The backend module permits actions against any frontend user in the system: logout, confirmation, refusal, and resending a user confirmation.
3
Which versions are affected?
femanager extension 7.x versions before 7.2.3 are affected.