Insecure Direct Object Reference Vulnerability in TYPO3 sr_feuser_register Extension
CVE-2025-48205

8.6HIGH

Key Information:

Vendor

Typo3

Vendor
CVE Published:
21 May 2025

What is CVE-2025-48205?

The sr_feuser_register extension for TYPO3, up to version 12.4.8, contains a vulnerability that allows attackers to exploit insecure direct object references. This flaw enables unauthorized access to sensitive user data, potentially leading to data leakage and manipulation. It is crucial for administrators to apply the necessary patches and follow best security practices to mitigate risks associated with this vulnerability.

Affected Version(s)

sr feuser register extension 5.1.0 < 12.5.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.