Executive brief
The femanager extension for TYPO3 fails to properly validate which user groups a logged-in user can assign to themselves during profile editing. An attacker can exploit this to grant themselves access to administrative or restricted frontend user groups without authorization, effectively escalating their privileges within the system.
Technical details
The vulnerability is a broken access control flaw (CWE-862, CWE-863) in the femanager extension's profile edit plugin. When configured with default field settings, the extension does not restrict which frontend usergroups a user may assign to their own account during profile editing. An authenticated user with normal access can send profile update requests assigning themselves to arbitrary frontend groups, including privileged ones, without verification. This is a self-service privilege escalation requiring only an existing login to the frontend. Fixed versions 6.4.5, 7.5.5, 8.4.2, and 13.3.5 address this issue.
Affected products
- in2code femanager 6.4.4 and below, 7.0.0-7.5.4, 8.0.0-8.4.1, 13.0.0-13.3.4
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Versions 6.4.5, 7.5.5, 8.4.2, and 13.3.5 released