Authorization Bypass Through User-Controlled Key
CVE-2025-7899
Summary
The powermail extension for TYPO3 allows an Insecure Direct Object Reference (IDOR), resulting in the download of arbitrary files from the web server. This issue affects in2code/powermail versions 12.0.0 through 12.5.2, and 13.0.0.
- LOW
- NETWORK
- NONE
- LOW
CWE-639 - Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References
Advisory Timeline
- Published