The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://typo3.org/security/advisory/typo3-ext-sa-2025-009 |
![]() ![]() |
History
Tue, 22 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0 | |
Title | Insecure Direct Object Reference in extension "powermail" (powermail) | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: TYPO3
Published: 2025-07-22T10:18:38.449Z
Updated: 2025-07-22T14:18:12.927Z
Reserved: 2025-07-19T12:40:12.631Z
Link: CVE-2025-7899

Updated: 2025-07-22T14:18:07.559Z

Status : Awaiting Analysis
Published: 2025-07-22T11:15:24.157
Modified: 2025-07-22T13:05:40.573
Link: CVE-2025-7899

No data.