GHSA-377v-8637-6vq6 · Severity: medium · Ecosystem: composer — TYPO3 femanager extension allows remote frontend users to modify or delete records of other frontend users
The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.
Conclusion & alert: CVE-2014-6292 is rated Moderate Risk (50.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.33%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.35% | 1.33% | +0.98% |
| 2 | 2025-03-23 | 0.26% | 0.35% | +0.09% |
| 3 | 2025-03-17 | — | 0.26% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.4 | 2.0 | MEDIUM |
|
10.0 | 4.9 | [email protected] |
GHSA-377v-8637-6vq6 · Severity: medium · Ecosystem: composer — TYPO3 femanager extension allows remote frontend users to modify or delete records of other frontend users
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| in2code | femanager | <= 1.0.8 | cpe:2.3:a:in2code:femanager:*:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.0 | cpe:2.3:a:in2code:femanager:1.0.0:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.1 | cpe:2.3:a:in2code:femanager:1.0.1:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.2 | cpe:2.3:a:in2code:femanager:1.0.2:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.3 | cpe:2.3:a:in2code:femanager:1.0.3:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.4 | cpe:2.3:a:in2code:femanager:1.0.4:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.5 | cpe:2.3:a:in2code:femanager:1.0.5:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.6 | cpe:2.3:a:in2code:femanager:1.0.6:*:*:*:*:typo3:*:* |
| in2code | femanager | 1.0.7 | cpe:2.3:a:in2code:femanager:1.0.7:*:*:*:*:typo3:*:* |
| URL | Tags |
|---|---|
| http://typo3.org/extensions/repository/view/femanager | Patch |
| http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-002/ | Patch Vendor Advisory |