5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
Basic Information
ID
CVE-2025-7900
Source
TYPO3
Published
Jul 22, 2025 at 10:21
Modified
Jul 22, 2025 at 14:17
Affected Product
Vendor
TYPO3
Product
Extension "femanager"
Version
8.0.0
Affected Versions
TYPO3 Extension "femanager" 8.0.0
TYPO3 Extension "femanager" 7.0.0
TYPO3 Extension "femanager" 0
TYPO3 Extension "femanager" 7.0.0
TYPO3 Extension "femanager" 0