PatchSiren cyber security CVE debrief
CVE-2023-50460 TYPO3 CVE debrief
CVE-2023-50460 is a vulnerability in the femanager extension for TYPO3, allowing an authenticated backend user to perform actions on any frontend user. The CVE record was published on 2026-09-14T07:17:15.510Z. This vulnerability affects TYPO3 systems using the femanager extension. Defenders should assess exposure and prioritize verification of TYPO3 systems using the femanager extension. The vulnerability allows various actions such as userLogout, confirmUser, refuseUser, and resendUserConfirmation for any frontend user in the system.
- Vendor
- TYPO3
- Product
- femanager
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-22
Who should care
TYPO3 administrators and security teams should assess exposure and prioritize verification of TYPO3 systems using the femanager extension. They should also ensure that backend users' access is properly restricted to prevent unauthorized actions. Additionally, they should monitor for suspicious activity related to frontend user accounts and review compensating controls for exposed systems.
Why it matters
CVE-2023-50460 is a medium-severity vulnerability in the femanager extension for TYPO3, allowing authenticated backend users to perform actions on any frontend user. Defenders should prioritize verifying exposure and ensuring proper access controls.
- Potential unauthorized actions on frontend user accounts
- Increased risk of account takeover or manipulation
- Need for verification of TYPO3 system exposure and backend user access controls
Technical summary
The femanager extension for TYPO3 allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system. This vulnerability exists in the femanager extension 7.x before 7.2.3 for TYPO3. The vulnerability allows an authenticated backend user to perform actions on any frontend user, potentially leading to unauthorized actions on frontend user accounts and increased risk of account takeover or manipulation. Defenders should prioritize verifying exposure and ensuring proper access controls.
Defensive priority
Defenders should prioritize verifying exposure of TYPO3 systems using the femanager extension and ensuring that backend users' access is properly restricted.
Recommended defensive actions
- Verify exposure of TYPO3 systems using the femanager extension
- Restrict backend user access to prevent unauthorized actions
- Monitor for suspicious activity related to frontend user accounts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, but indicate that it affects the femanager extension for TYPO3. The vulnerability has been confirmed to exist in the femanager extension 7.x before 7.2.3 for TYPO3. However, specific details about the vulnerability, such as the version of TYPO3 affected and the exact nature of the vulnerability, are not provided. Defenders should verify the exposure of TYPO3 systems using the femanager extension and ensure proper access controls.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-50460 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-50460
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-50460 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-50460
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://typo3.org/security/advisory/typo3-ext-sa-2023-010
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.