PT-2025-22374 · Typo3 · Sr Feuser Register

Published

2025-05-20

·

Updated

2025-12-27

·

CVE-2025-48205

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions sr feuser register extension for TYPO3 versions through 12.4.8
Description The issue allows for Insecure Direct Object Reference, enabling attackers to read arbitrary files. This could potentially lead to unauthorized access to sensitive information.
Recommendations For versions through 12.4.8, consider disabling the sr feuser register extension until a patch is available to prevent exploitation. Restrict access to sensitive files and directories to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

BDU:2025-06007
CVE-2025-48205
GHSA-CVGC-MX2W-H3W8

Affected Products

Sr Feuser Register