SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2023-50460

MEDIUM · CVSS 5.4 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The femanager extension for TYPO3 versions prior to 7.2.3 contains a vulnerability that allows authenticated backend users to manipulate frontend user accounts, including logging out users and confirming or refusing their accounts. This could lead to unauthorized access or account management issues, potentially compromising user data and system integrity. Organizations using affected versions of TYPO3 should prioritize patching this vulnerability to mitigate risks associated with unauthorized user actions.

CVE
CVE-2023-50460
Severity
MEDIUM
CVSS
5.4
EPSS
0.24%

Original NVD Description

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.