CVE Vulnerabilities

CVE-2022-44543

Published: Dec 12, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.

Affected Software

NameVendorStart VersionEnd Version
FemanagerIn2code*5.5.2 (excluding)
FemanagerIn2code6.0.0 (including)6.3.3 (excluding)
FemanagerIn2code7.0.0 (including)7.0.0 (including)

References