PT-2025-30395 · Typo3 · Femanager

Alexander Freundlieb

·

Published

2025-07-22

·

Updated

2025-07-22

·

CVE-2025-7900

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions femanager versions 6.4.1 and below femanager versions 7.0.0 through 7.5.2 femanager versions 8.0.0 through 8.3.0
Description The femanager extension for TYPO3 contains an Insecure Direct Object Reference issue, which allows unauthorized modification of userdata.
Recommendations Update femanager to a version later than 6.4.1. Update femanager to a version later than 7.5.2. Update femanager to a version later than 8.3.0.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-7900
GHSA-RC5F-3HFV-JXP2

Affected Products

Femanager