PT-2025-30394 · Typo3 · Powermail

Published

2025-07-22

·

Updated

2025-07-22

·

CVE-2025-7899

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions powermail versions 12.0.0 through 12.5.2 powermail version 13.0.0
Description The powermail extension for TYPO3 contains an Insecure Direct Object Reference issue that allows for the download of arbitrary files from the webserver.
Recommendations Update powermail to a version later than 12.5.2. Update powermail to a version later than 13.0.0.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-7899
GHSA-X769-3CWV-F8HC

Affected Products

Powermail