The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
History

Tue, 22 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
Description The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0
Title Insecure Direct Object Reference in extension "femanager" (femanager)
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published: 2025-07-22T10:21:32.123Z

Updated: 2025-07-22T14:17:04.005Z

Reserved: 2025-07-19T12:40:19.076Z

Link: CVE-2025-7900

cve-icon Vulnrichment

Updated: 2025-07-22T14:16:49.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-22T11:15:24.340

Modified: 2025-07-22T13:05:40.573

Link: CVE-2025-7900

cve-icon Redhat

No data.