Insecure Direct Object Reference in extension "powermail" (powermail)
Vulnerability Description
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7899
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Riny van Tiggelen
More from TYPO3
View All →Affected Vendor
TYPO3
View all reports →