GHSA-xxwr-wv9g-7jw3

Suggest an improvement
Source
https://github.com/advisories/GHSA-xxwr-wv9g-7jw3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-xxwr-wv9g-7jw3/GHSA-xxwr-wv9g-7jw3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xxwr-wv9g-7jw3
Aliases
  • CVE-2025-48202
Published
2025-05-21T17:19:30Z
Modified
2025-05-21T19:38:02.789293Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C CVSS Calculator
Summary
The femanager TYPO3 extension allows Insecure Direct Object Reference
Details

Insecure Direct Object Reference (IDOR) in the femanager TYPO3 extension allows attackers to view frontend user data via a user parameter in the newAction of the newController.

Database specific
{
    "nvd_published_at": "2025-05-21T16:15:32Z",
    "cwe_ids": [
        "CWE-284",
        "CWE-425",
        "CWE-639"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-21T17:19:30Z"
}
References

Affected packages

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.0.0
Fixed
8.2.2

Affected versions

8.*

8.0.0
8.0.1
8.1.0
8.2.0
8.2.1

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.4.2

Affected versions

7.*

7.0.0
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.2.2
7.2.3
7.3.0
7.4.0
7.4.1

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.4.1

Affected versions

6.*

6.0.0
6.0.1
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.3.3
6.3.4
6.3.5
6.3.6
6.4.0

Packagist / in2code/femanager

Package

Name
in2code/femanager
Purl
pkg:composer/in2code/femanager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.5.5

Affected versions

5.*

5.5.0
5.5.1
5.5.2
5.5.3
5.5.4