The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.
https://typo3.org/security/advisory/typo3-ext-sa-2023-008
Source: Mitre, NVD
Published: 2026-09-14
Updated: 2026-09-22
Base Score: 3.6
Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N
Severity: Low
Base Score: 4.2
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity: Medium
EPSS: 0.01077