CVE-2022-44543
Last modified
CVE-2022-44543 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| In2code | Femanager | < 5.5.2 |
| In2code | Femanager | >= 6.0.0, < 6.3.3 |
| In2code | Femanager | 7.0.0 |
References
- https://typo3.org/help/security-advisoriesVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2022-015Vendor Advisory
- https://typo3.org/help/security-advisoriesVendor Advisory
- https://typo3.org/security/advisory/typo3-ext-sa-2022-015Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-44543?
How severe is CVE-2022-44543?
How do I fix CVE-2022-44543?
Are you affected by CVE-2022-44543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
