CVE-2023-50459: TYPO3 Femanager

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.

Affected products

  • TYPO3 Femanager: from 7.0.0, before 7.2.3 (fixed in 7.2.3)

Published 2026-09-14. Last modified 2026-09-22.