Description
The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- TYPO3 / femanager extension5.5.0 – 5.5.5
- TYPO3 / femanager extension6.0.0 – 6.4.1
- TYPO3 / femanager extension7.0.0 – 7.4.2
- TYPO3 / femanager extension8.0.0 – 8.2.2