Executive brief
The femanager extension for TYPO3 (a popular open-source content management system) contains a broken access control vulnerability in its backend module. An authenticated backend administrator can perform unauthorized actions on frontend user accounts, including logging users out, confirming or refusing user registrations, and resending confirmation emails—actions that should require explicit authorization per user. This allows a malicious or compromised administrative account to disrupt service for frontend users and potentially prevent legitimate users from accessing the system.
Technical details
The femanager extension (versions 7.0.0 through 7.2.2) fails to enforce proper authorization checks in its backend module. An authenticated backend user with access to the femanager backend module can call actions such as userLogout, confirmUser, refuseUser, and resendUserConfirmation on any frontend user account without additional permission validation. The vulnerability is a classic broken access control issue (CWE-284) affecting the backend module component. The attack requires valid backend user credentials and network access to the TYPO3 backend interface, but no additional user interaction. An attacker can arbitrarily manage frontend user accounts, including disabling or manipulating user status. Version 7.2.3 and later include proper authorization checks and should be applied immediately.
Affected products
- TYPO3 femanager 7.0.0 to 7.2.2
Timeline
- 2023-12-13: disclosed
- 2023-12-13: patched: Version 7.2.3 released