Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mm8v-wmqx-8h2j: Broken Access Control in 3rd party TYPO3 extension "femanager"

A missing access check in the InvitationController allows an unauthenticated user with a valid invitation link to set the password of all frontend users.

ghsa
#git#auth

Broken Access Control in 3rd party TYPO3 extension “femanager”

High severity GitHub Reviewed Published Feb 2, 2023 to the GitHub Advisory Database • Updated Feb 8, 2023

ghsa: Latest News

GHSA-pxg6-pf52-xh8x: cookie accepts cookie name, path, and domain with out of bounds characters