GHSA-4xp5-hr35-84cx

    Dashboard / Vulnerabilities / GHSA-4xp5-hr35-84cx

    GHSA-4xp5-hr35-84cx

    Published: 13 Dec 2023Last Modified: 30 Nov 2024

    Summary: Broken Access Control in extension "femanager"

    Details: The extension fails to check access permissions for the edit user component. An authenticated frontend user can use the vulnerability to either edit data of various frontend users or to delete various frontend user accounts. Another missing access check in the backend module of the extensions allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser and resendUserConfirmation) for any frontend user in the system.

    Affected packages

    Package

    Name: in2code/femanager

    Purl: pkg:composer/in2code/femanager

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 7.0.0
    Fixed -7.2.3

    Affected versions

    7.0.0
    7.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4xp5-hr35-84cx | CVE-DB