CVE-2025-48200: Critical severity typo3 sr_feuser_register vulnerability
Published May 21, 2025
·Updated
The srfeuserregister extension through 12.4.8 for TYPO3 allows Remote Code Execution via unsafe deserialization.
Affected Software
2 affected componentsFixes available
Typo3 sr_feuser_register<=12.4.8
composer/sjbr/sr-feuser-register>=5.1.0<12.5.0
12.5.0
Event History
May 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·07:52 PM
Data Sourced
via GitHub·07:52 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48200?
CVE-2025-48200 has a critical severity rating due to its potential for Remote Code Execution.
2
How do I fix CVE-2025-48200?
To fix CVE-2025-48200, upgrade the sr_feuser_register extension to version 12.4.9 or later.
3
Which versions of TYPO3 are affected by CVE-2025-48200?
CVE-2025-48200 affects TYPO3 sr_feuser_register extensions up to and including version 12.4.8.
4
What type of vulnerability is CVE-2025-48200?
CVE-2025-48200 is classified as a Remote Code Execution vulnerability.
5
Who is affected by CVE-2025-48200?
Any TYPO3 users utilizing the sr_feuser_register extension version 12.4.8 or earlier are at risk from CVE-2025-48200.