6
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0
Basic Information
ID
CVE-2025-7899
Source
TYPO3
Published
Jul 22, 2025 at 10:18
Modified
Jul 22, 2025 at 14:18
Affected Product
Vendor
TYPO3
Product
Extension "powermail"
Version
12.0.0
Affected Versions
TYPO3 Extension "powermail" 12.0.0
TYPO3 Extension "powermail" 13.0.0
TYPO3 Extension "powermail" 13.0.0