CVE-2025-48202: Medium severity typo3 femanager vulnerability
Insecure Direct Object Reference (IDOR) in the femanager TYPO3 extension allows attackers to view frontend user data via a user parameter in the newAction of the newController.
Other sources
The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48202?
CVE-2025-48202 is classified as a medium severity vulnerability due to the potential for unauthorized access to sensitive user data.
How do I fix CVE-2025-48202?
To fix CVE-2025-48202, update the femanager extension to version 8.2.2 or later.
What software is affected by CVE-2025-48202?
CVE-2025-48202 affects the TYPO3 femanager extension versions up to and including 8.2.1.
What kind of vulnerability is CVE-2025-48202?
CVE-2025-48202 is an Insecure Direct Object Reference (IDOR) vulnerability.
Who can be impacted by CVE-2025-48202?
Users of the TYPO3 femanager extension who have not updated to the patched version may be impacted by CVE-2025-48202.