---
id: CVE-2023-50459
title: An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3
summary: >-
  An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3.
  It fails to check access permissions for the edit user component. An
  authenticated frontend user can exploit this to either edit data of various
  frontend user…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-863
vendor: TYPO3
product: femanager
affected:
  - femanager >= 7.0.0 < 7.2.3
published: '2026-09-14'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-50459'
references:
  - url: 'https://typo3.org/security/advisory/typo3-ext-sa-2023-010'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00417
epssPercentile: 0.3327
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T14:58:20.873827Z'
ingestedAt: '2026-09-14T15:23:07.420Z'
---

## Overview

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
