Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
12.0.0 (semver)
affected
13.0.0 (semver)
affected
Description
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
12.0.0 (semver)
13.0.0 (semver)
Credits
Riny van Tiggelen
References
typo3.org/security/advisory/typo3-ext-sa-2025-009