-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| in2code/femanager | composer | >= 7.0.0, < 7.2.3 | 7.2.3 |
The vulnerability description explicitly identifies two attack vectors: 1) Frontend user editing/deletion without proper access checks, and 2) Backend user actions (userLogout, confirmUser, refuseUser, resendUserConfirmation) without authorization. In TYPO3 extensions, these would map to specific controller actions. The high confidence comes from the advisory's direct mention of these specific action names and component types (frontend edit/delete, backend module actions), combined with standard extension architecture patterns where these functionalities would be implemented as discrete controller actions.
KEV Misses 88% of Exploited CVEs- Get the report