Executive brief
The femanager extension for TYPO3 (a popular content management system) fails to properly verify user permissions when editing user profiles. An attacker with a frontend user account can modify or delete other users' accounts without authorization, compromising user data integrity and account security across the platform.
Technical details
The vulnerability is a broken access control (CWE-284) flaw in the femanager extension's edit user component. An authenticated frontend user can exploit insufficient permission checks to modify arbitrary frontend user data or delete user accounts. The vulnerability affects versions 7.0.0 through 7.2.2 and is exploitable over the network by any authenticated frontend user without user interaction required. A similar access control flaw in the backend module allows authenticated backend users to perform unauthorized actions on any frontend user. The issue has been patched in version 7.2.3.
Affected products
- in2code femanager 7.0.0 to 7.2.2
Timeline
- 2023-12-13: disclosed
- 2023-12-13: patched: Version 7.2.3 released