QID 996272
Date Published: 2023-12-14
QID 996272: PHP (Composer) Security Update for in2code/femanager (GHSA-4xp5-hr35-84cx)
The extension fails to check access permissions for the edit user component. An authenticated frontend user can use the vulnerability to either edit data of various frontend users or to delete various frontend user accounts.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4xp5-hr35-84cx for updates and patch information.
Vendor References
- GHSA-4xp5-hr35-84cx -
github.com/advisories/GHSA-4xp5-hr35-84cx
CVEs related to QID 996272
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4xp5-hr35-84cx | in2code/femanager |
|