CVE Vulnerabilities

CVE-2025-48205

Direct Request ('Forced Browsing')

Published: May 21, 2025 | Modified: May 21, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Potential Mitigations

References