CVE-2025-7900: Insecure Direct Object Reference in extension "femanager" (femanager)
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/in2code/femanagerto a version that resolves this vulnerability.Fixed in 8.3.1 - Upgrade
Upgrade
composer/in2code/femanagerto a version that resolves this vulnerability.Fixed in 7.5.3 - Upgrade
Upgrade
composer/in2code/femanagerto a version that resolves this vulnerability.Fixed in 6.4.2 - Compensating control
Mitigate the Insecure Direct Object Reference in TYPO3 extension "femanager" by restricting access to the femanager endpoints (routes/controllers that modify userdata) to authorized users/roles only, until the extension is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7900?
CVE-2025-7900 is classified as a medium severity vulnerability due to its potential for unauthorized modification of userdata.
How do I fix CVE-2025-7900?
To fix CVE-2025-7900, upgrade the femanager extension to version 8.3.1 or later.
What versions of femanager are affected by CVE-2025-7900?
CVE-2025-7900 affects femanager versions 6.4.1 and below, 7.0.0 to 7.5.2, and 8.0.0 to 8.3.0.
What type of vulnerability is CVE-2025-7900?
CVE-2025-7900 is an Insecure Direct Object Reference vulnerability.
What does CVE-2025-7900 allow attackers to do?
CVE-2025-7900 allows attackers to modify userdata without proper authorization.