CVE-2023-45023
TYPO3 extension femanager Broken Access Control vulnerability
Description
femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.
How to fix CVE-2023-45023
To remediate CVE-2023-45023, upgrade the affected package to a fixed version below.
- Packagist/in2code/femanager—upgrade to 7.2.2 or later
Is CVE-2023-45023 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2023-45023.
Affected packages (1)
- >= 7.0.0, < 7.2.2