GHSA-59m9-p6cm-94q5

Suggest an improvement
Source
https://github.com/advisories/GHSA-59m9-p6cm-94q5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-59m9-p6cm-94q5/GHSA-59m9-p6cm-94q5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-59m9-p6cm-94q5
Aliases
Published
2022-11-03T18:10:52Z
Modified
2024-11-30T05:37:26.716134Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
TYPO3 Extension femanager vulnerable to Broken Access Control
Details

The TYPO3 Extension femanager prior to versions 5.5.2, 6.3.3, and 7.0.1 is vulnerable to broken access control. The usergroup.inList validation can be bypassed resulting in new frontend users created by the extension may be members of groups that are restricted. The vulnerability is only exploitable if the field usergroup is available in the registration form. Versions 5.5.2, 6.3.3, and 7.0.1 contain patches.

Database specific
{
    "nvd_published_at": "2023-12-12T17:15:07Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-11-03T18:10:52Z"
}
References

Affected packages

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.1

Affected versions

7.*

7.0.0

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.3.3

Affected versions

6.*

6.0.0
6.0.1
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.2

Affected versions

2.*

2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0

3.*

3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.3.0

4.*

4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5

5.*

5.0.0
5.1.0
5.1.1
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.4.2
5.5.0
5.5.1