{"id":"CVE-2022-44543","details":"The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.","aliases":["GHSA-59m9-p6cm-94q5"],"modified":"2026-08-12T03:51:12.768113723Z","published":"2023-12-12T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/44xxx/CVE-2022-44543.json","unresolved_ranges":[{"extracted_events":[{"fixed":"5.5.2"},{"introduced":"6.x"},{"fixed":"6.3.3"},{"introduced":"7.x"},{"fixed":"7.0.1"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/44xxx/CVE-2022-44543.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-44543"},{"type":"ADVISORY","url":"https://typo3.org/help/security-advisories"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2022-015"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/in2code-de/femanager","events":[{"introduced":"0"},{"fixed":"166ea2116d6669b8fde34362ba52d6e30f8231db"},{"introduced":"9a09b57bb3f4b30a8aeafe6da114f81030495bc4"},{"fixed":"cc40e78876647d1e76cfe7d9040d1704515b6003"},{"introduced":"15223fcc5ef859785b8648980e2dfaf9ac6b4b7c"},{"last_affected":"15223fcc5ef859785b8648980e2dfaf9ac6b4b7c"}],"database_specific":{"cpe":["cpe:2.3:a:in2code:femanager:*:*:*:*:*:typo3:*:*","cpe:2.3:a:in2code:femanager:7.0.0:*:*:*:*:typo3:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"5.5.2"},{"introduced":"6.0.0"},{"fixed":"6.3.3"},{"introduced":"7.0.0"},{"last_affected":"7.0.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["7.0.0","5.5.1","6.3.1","5.5.0","5.4.2","5.4.1","5.4.0","5.3.1","5.3.0","5.2.0","5.1.1","5.1.0","5.0.0","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.2.0","4.1.1","2.6.0","4.1.0","4.0.2","4.0.1","4.0.0","3.3.0","3.2.0","3.1.3","3.1.2","3.1.1","3.1.0","3.0.2","3.0.1","3.0.0","2.5.1","2.5.0","2.4.0","2.3.0","2.2.0","2.1.0","2.0.1","2.0.0","1.5.2","1.5.0","1.5.1","1.4.3","1.4.2","1.4.1","1.4.0","1.2.0","1.0.10","1.0.8","1.0.7","1.0.6","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-44543.json"}}],"schema_version":"1.9.0"}