PT-2025-30394 · Typo3 · Powermail

CVE-2025-7899

·

Published

2025-07-22

·

Updated

2025-07-22

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions powermail versions 12.0.0 through 12.5.2 powermail version 13.0.0
Description The powermail extension for TYPO3 contains an Insecure Direct Object Reference issue that allows for the download of arbitrary files from the webserver.
Recommendations Update powermail to a version later than 12.5.2. Update powermail to a version later than 13.0.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7899
GHSA-X769-3CWV-F8HC

Affected Products

Powermail