Insecure Direct Object Reference in TYPO3 Powermail Extension
CVE-2025-7899
6MEDIUM
What is CVE-2025-7899?
The Powermail extension for TYPO3 is affected by a security flaw that enables an attacker to exploit an Insecure Direct Object Reference (IDOR). This vulnerability allows for unauthorized access and download of arbitrary files from the webserver, potentially leading to sensitive data exposure. Users of Powermail versions 12.0.0 through 12.5.2 and 13.0.0 should take immediate action to protect their installations.
Affected Version(s)
Extension "powermail" 12.0.0 <= 12.5.2
Extension "powermail" 13.0.0
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Riny van Tiggelen
