CyberRota Analysis
AI-GeneratedThe femanager extension for TYPO3 versions prior to 7.2.3 contains a vulnerability that allows authenticated backend users to manipulate frontend user accounts, including logging out users and confirming or refusing their accounts. This could lead to unauthorized access or account management issues, potentially compromising user data and system integrity. Organizations using affected versions of TYPO3 should prioritize patching this vulnerability to mitigate risks associated with unauthorized user actions.
Original NVD Description
An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.