CVE-2022-44543
TYPO3 Extension femanager vulnerable to Broken Access Control
6.5
MEDIUM
CVSS 3.1
EPSS 0.60%
Description
The TYPO3 Extension femanager prior to versions 5.5.2, 6.3.3, and 7.0.1 is vulnerable to broken access control. The `usergroup.inList` validation can be bypassed resulting in new frontend users created by the extension may be members of groups that are restricted. The vulnerability is only exploitable if the field usergroup is available in the registration form. Versions 5.5.2, 6.3.3, and 7.0.1 contain patches.
How to fix CVE-2022-44543
To remediate CVE-2022-44543, upgrade the affected package to a fixed version below.
- —upgrade to 7.0.1 or later
Is CVE-2022-44543 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.0.0, < 7.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |