Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-93j4-v838-8767: TYPO3 extension femanager Broken Access Control vulnerability

femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.

ghsa
#vulnerability#git

TYPO3 extension femanager Broken Access Control vulnerability

Moderate severity GitHub Reviewed Published Oct 4, 2023 to the GitHub Advisory Database • Updated Oct 4, 2023

ghsa: Latest News

GHSA-pxg6-pf52-xh8x: cookie accepts cookie name, path, and domain with out of bounds characters