Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22305 | Femanager extension for TYPO3 allows Insecure Direct Object Reference |
Github GHSA |
GHSA-rc5f-3hfv-jxp2 | Femanager extension for TYPO3 allows Insecure Direct Object Reference |
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2025-010 |
|
Tue, 07 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 typo3 |
|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0 | |
| Title | Insecure Direct Object Reference in extension "femanager" (femanager) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2025-07-22T14:17:04.005Z
Reserved: 2025-07-19T12:40:19.076Z
Link: CVE-2025-7900
Updated: 2025-07-22T14:16:49.583Z
Status : Analyzed
Published: 2025-07-22T11:15:24.340
Modified: 2025-10-07T20:32:46.950
Link: CVE-2025-7900
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA