{"id":"GHSA-93j4-v838-8767","summary":"TYPO3 extension femanager Broken Access Control vulnerability","details":"femanager fails to check access permissions for the invitation component. Depending on the configuration of the plugin, a remote user can create frontend user accounts with access to configured frontend groups.","aliases":["CVE-2023-45023"],"modified":"2024-11-28T05:44:52.248341Z","published":"2023-10-04T17:57:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-10-04T17:57:18Z","nvd_published_at":null,"cwe_ids":["CWE-287"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/in2code-de/femanager/commit/cc5f2893613a6b3fd2677c457574ab587a0862ca"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/in2code/femanager/CVE-2023-45023.yaml"},{"type":"PACKAGE","url":"https://github.com/in2code-de/femanager"},{"type":"WEB","url":"https://github.com/in2code-de/femanager/releases/tag/7.2.2"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2023-008"}],"affected":[{"package":{"name":"in2code/femanager","ecosystem":"Packagist","purl":"pkg:composer/in2code/femanager"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.2.2"}]}],"versions":["7.0.0","7.0.1","7.1.0","7.1.1","7.2.0","7.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-93j4-v838-8767/GHSA-93j4-v838-8767.json"}}],"schema_version":"1.9.0"}