CVE 5.3 MEDIUM

Insecure Direct Object Reference in extension “femanager” (femanager)_CVE-2025-7900

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0

Basic Information

ID CVE-2025-7900
Source TYPO3
Published Jul 22, 2025 at 10:21
Modified Jul 22, 2025 at 14:17

Affected Product

Vendor TYPO3
Product Extension "femanager"
Version 8.0.0
Affected Versions TYPO3 Extension "femanager" 8.0.0
TYPO3 Extension "femanager" 7.0.0
TYPO3 Extension "femanager" 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.