SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2023-45023

MEDIUM · CVSS 4.2 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The femanager extension for TYPO3 versions prior to 7.2.2 is vulnerable due to improper access control in its invitation component, allowing unauthorized users to potentially send invitations without proper permissions. This could lead to unauthorized access and manipulation of user accounts. TYPO3 administrators using affected versions should prioritize updating to mitigate the risk of exploitation.

CVE
CVE-2023-45023
Severity
MEDIUM
CVSS
4.2
EPSS
0.13%

Original NVD Description

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.