CVE Watchtower

← Back to CVE List

CVE-2023-50459NVD

Description

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.
Severity Level
MEDIUM (5.4)
Published Date
14/09/2026
Last Modified
14/09/2026
Exploitation Status
????
EPSS Score
0.24% (percentile 15.1%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Weaknesses (CWE)

CWE-863 - CWE-863 Incorrect Authorization

Affected & Patched Versions

ProductAffected VersionsPatched Version
TYPO3 femanager7.0.0 - < 7.2.3N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.