CyberRota Analysis
AI-GeneratedThe femanager extension for TYPO3 versions prior to 7.2.2 is vulnerable due to improper access control in its invitation component, allowing unauthorized users to potentially send invitations without proper permissions. This could lead to unauthorized access and manipulation of user accounts. TYPO3 administrators using affected versions should prioritize updating to mitigate the risk of exploitation.
CVE
CVE-2023-45023
Severity
MEDIUM
CVSS
4.2
EPSS
0.13%
Original NVD Description
The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.