PT-2026-81235 · Typo3+1 · Femanager Extension+1
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The user detail view of the extension does not verify if the requested user record matches the configured or logged-in target. This allows visitors with access to the Detail or List plugin to retrieve profile data of other frontend users, such as name, email, date of birth, and address, by providing an arbitrary
user ID.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Femanager Extension
Femanager