CVE-2023-50460: TYPO3 Femanager

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.

Affected products

  • TYPO3 Femanager: from 7.0.0, before 7.2.3 (fixed in 7.2.3)

Published 2026-09-14. Last modified 2026-09-22.