PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-50460 TYPO3 CVE debrief

CVE-2023-50460 is a vulnerability in the femanager extension for TYPO3, allowing an authenticated backend user to perform actions on any frontend user. The CVE record was published on 2026-09-14T07:17:15.510Z. This vulnerability affects TYPO3 systems using the femanager extension. Defenders should assess exposure and prioritize verification of TYPO3 systems using the femanager extension. The vulnerability allows various actions such as userLogout, confirmUser, refuseUser, and resendUserConfirmation for any frontend user in the system.

Vendor
TYPO3
Product
femanager
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-22
Advisory published
2026-09-14
Advisory updated
2026-09-22

Who should care

TYPO3 administrators and security teams should assess exposure and prioritize verification of TYPO3 systems using the femanager extension. They should also ensure that backend users' access is properly restricted to prevent unauthorized actions. Additionally, they should monitor for suspicious activity related to frontend user accounts and review compensating controls for exposed systems.

Why it matters

CVE-2023-50460 is a medium-severity vulnerability in the femanager extension for TYPO3, allowing authenticated backend users to perform actions on any frontend user. Defenders should prioritize verifying exposure and ensuring proper access controls.

  • Potential unauthorized actions on frontend user accounts
  • Increased risk of account takeover or manipulation
  • Need for verification of TYPO3 system exposure and backend user access controls

Technical summary

The femanager extension for TYPO3 allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system. This vulnerability exists in the femanager extension 7.x before 7.2.3 for TYPO3. The vulnerability allows an authenticated backend user to perform actions on any frontend user, potentially leading to unauthorized actions on frontend user accounts and increased risk of account takeover or manipulation. Defenders should prioritize verifying exposure and ensuring proper access controls.

Defensive priority

Defenders should prioritize verifying exposure of TYPO3 systems using the femanager extension and ensuring that backend users' access is properly restricted.

Recommended defensive actions

  • Verify exposure of TYPO3 systems using the femanager extension
  • Restrict backend user access to prevent unauthorized actions
  • Monitor for suspicious activity related to frontend user accounts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, but indicate that it affects the femanager extension for TYPO3. The vulnerability has been confirmed to exist in the femanager extension 7.x before 7.2.3 for TYPO3. However, specific details about the vulnerability, such as the version of TYPO3 affected and the exact nature of the vulnerability, are not provided. Defenders should verify the exposure of TYPO3 systems using the femanager extension and ensure proper access controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-50460 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-50460

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-50460 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-50460

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.