The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2025-010 |
|
History
Tue, 07 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 typo3 |
|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0 | |
| Title | Insecure Direct Object Reference in extension "femanager" (femanager) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published: 2025-07-22T10:21:32.123Z
Updated: 2025-07-22T14:17:04.005Z
Reserved: 2025-07-19T12:40:19.076Z
Link: CVE-2025-7900
Updated: 2025-07-22T14:16:49.583Z
Status : Analyzed
Published: 2025-07-22T11:15:24.340
Modified: 2025-10-07T20:32:46.950
Link: CVE-2025-7900
No data.