CVE-2025-7899 Details
Description
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0
A vulnerability in the Powermail extension for TYPO3 allows for Insecure Direct Object Reference (IDOR), enabling authenticated users with access to the backend module to download arbitrary files from the web server. This issue affects Powermail versions 12.0.0 prior to 12.5.2 and 13.0.0. The vulnerability arises because the extension does not properly validate the 'file' query parameter in the 'downloadFile' function of the backend module. Exploitation requires at least one Powermail email record containing an uploaded file to be available in the backend.
Users are advised to update to Powermail versions 12.5.3 or 13.0.1, available through the TYPO3 Extension Manager, Packagist, or directly from the TYPO3 Extension Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 22, 2025CISA-ADP
Assessed Jul 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2025-009 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 powermail | >= 12.0.0, <= 12.5.2 (semver) 13.0.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2025 | New CVE Received | TYPO3 |
Volerion