Description
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22306 | Powermail extension for TYPO3 allows Insecure Direct Object Reference |
Github GHSA |
GHSA-x769-3cwv-f8hc | Powermail extension for TYPO3 allows Insecure Direct Object Reference |
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2025-009 |
|
History
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0 | |
| Title | Insecure Direct Object Reference in extension "powermail" (powermail) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2025-07-22T14:18:12.927Z
Reserved: 2025-07-19T12:40:12.631Z
Link: CVE-2025-7899
Updated: 2025-07-22T14:18:07.559Z
Status : Deferred
Published: 2025-07-22T11:15:24.157
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-7899
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA