CVE 6 MEDIUM

Insecure Direct Object Reference in extension “powermail” (powermail)_CVE-2025-7899

6 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0

Basic Information

ID CVE-2025-7899
Source TYPO3
Published Jul 22, 2025 at 10:18
Modified Jul 22, 2025 at 14:18

Affected Product

Vendor TYPO3
Product Extension "powermail"
Version 12.0.0
Affected Versions TYPO3 Extension "powermail" 12.0.0
TYPO3 Extension "powermail" 13.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.