CVE-2014-6292
medium
CVSS v3
—
CVSS v2
6.4
VIR risk
6.4
Description
TYPO3 femanager extension allows remote frontend users to modify or delete records of other frontend users
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-002/
Vendor advisory: cve@mitre.org — http://typo3.org/extensions/repository/view/femanager
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | in2code/femanager | <1.0.9 | 1.0.9 |
References
Verify integrity in audit chain (admin only). AS-IS.