{"id":"CVE-2023-45023","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-45023","summary":"TYPO3 extension femanager Broken Access Control vulnerability","details":"femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.","published":"2023-10-04T17:57:18Z","modified":"2024-11-28T05:44:52.248341Z","cvss":null,"epss":{"score":0.00133,"percentile":0.03241,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"in2code/femanager","fixedVersion":"7.2.2"}],"fix":{"url":"https://github.com/in2code-de/femanager/commit/cc5f2893613a6b3fd2677c457574ab587a0862ca","label":"in2code-de/femanager@cc5f289"},"references":[{"type":"WEB","url":"https://github.com/in2code-de/femanager/commit/cc5f2893613a6b3fd2677c457574ab587a0862ca"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/in2code/femanager/CVE-2023-45023.yaml"},{"type":"PACKAGE","url":"https://github.com/in2code-de/femanager"},{"type":"WEB","url":"https://github.com/in2code-de/femanager/releases/tag/7.2.2"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2023-008"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:44:52.248341Z"}}