CVE-2023-25014: IN2CODE Femanager
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
Affected products
- IN2CODE Femanager: before 5.5.3 (fixed in 5.5.3); from 6.0.0, before 6.3.4 (fixed in 6.3.4); from 7.0.0, before 7.1.0 (fixed in 7.1.0)
Published 2023-02-02. Last modified 2026-06-17.