CVE-2025-7899

MEDIUM

Powermail <13.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0

References (1)

Core 1

Scores

CVSS v4 6.0
EPSS 0.0009
EPSS Percentile 25.0%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (3)
in2code/powermail 12.0.0 - 12.5.3Packagist
TYPO3/Extension "powermail" 12.0.0 - 12.5.2
TYPO3/Extension "powermail" 13.0.0
Published Jul 22, 2025
Tracked Since Feb 18, 2026