Improper Access Control Affecting in2code/femanager package, versions <5.5.3 >=6.0.0, <6.3.4 >=7.0.0, <7.1.0
Threat Intelligence
EPSS
0.07% (31st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-IN2CODEFEMANAGER-3266772
- published 2 Feb 2023
- disclosed 2 Feb 2023
- credit Max Schäfer, Dennis Schober-Wenger
Introduced: 2 Feb 2023
CVE-2023-25014 Open this link in a new tabHow to fix?
Upgrade in2code/femanager
to version 5.5.3, 6.3.4, 7.1.0 or higher.
Overview
in2code/femanager is a Modern TYPO3 Frontend User Registration.
Affected versions of this package are vulnerable to Improper Access Control due to missing access checks in the InvitationController
which allow an unauthenticated user to delete all frontend users.
Note: This issue is only exploitable if the invitation component of the extension is configured and used on the website.
References
CVSS Scores
version 3.1