The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2025-010 |
|
History
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0 | |
| Title | Insecure Direct Object Reference in extension "femanager" (femanager) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published: 2025-07-22T10:21:32.123Z
Updated: 2025-07-22T14:17:04.005Z
Reserved: 2025-07-19T12:40:19.076Z
Link: CVE-2025-7900
Updated: 2025-07-22T14:16:49.583Z
Status : Awaiting Analysis
Published: 2025-07-22T11:15:24.340
Modified: 2025-07-22T13:05:40.573
Link: CVE-2025-7900
No data.