← Back

Femanager

femanager

Vendor: In2code • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1In2code
1Femanager
Nov 21, 2024
Dec 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because...Show more
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.Show less
1In2code
1Femanager
Mar 26, 2025
Feb 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend us...Show more
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.Show less
1In2code
1Femanager
Mar 26, 2025
Feb 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of al...Show more
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.Show less
1In2code
1Femanager
Nov 21, 2024
Aug 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
1In2code
1Femanager
May 6, 2026
Oct 3, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.