---
id: CVE-2023-50460
title: An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3
summary: >-
  An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3.
  The backend module allows an authenticated backend user to perform various
  actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for
  any f…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-863
vendor: TYPO3
product: femanager
affected:
  - femanager >= 7.0.0 < 7.2.3
published: '2026-09-14'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-50460'
references:
  - url: 'https://typo3.org/security/advisory/typo3-ext-sa-2023-010'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00238
epssPercentile: 0.1317
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T14:56:28.542681Z'
ingestedAt: '2026-09-14T15:23:07.465Z'
---

## Overview

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
