The femanager TYPO3 extension allows Insecure Direct Object Reference
Moderate severity
GitHub Reviewed
Published
May 21, 2025
to the GitHub Advisory Database
•
Updated May 21, 2025
Package
Affected versions
>= 8.0.0, < 8.2.2
>= 7.0.0, < 7.4.2
>= 6.0.0, < 6.4.1
>= 5.5.0, < 5.5.5
Patched versions
8.2.2
7.4.2
6.4.1
5.5.5
Description
Published by the National Vulnerability Database
May 21, 2025
Published to the GitHub Advisory Database
May 21, 2025
Reviewed
May 21, 2025
Last updated
May 21, 2025
Insecure Direct Object Reference (IDOR) in the femanager TYPO3 extension allows attackers to view frontend user data via a user parameter in the newAction of the newController.
References