CVE-2025-48205: High severity typo3 sr_feuser_register vulnerability
Published May 21, 2025
·Updated
The srfeuserregister extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
Affected Software
2 affected componentsFixes available
Typo3 sr_feuser_register extension<=12.4.8
composer/sjbr/sr-feuser-register>=5.1.0<12.5.0
12.5.0
Event History
May 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-48205?
CVE-2025-48205 is classified as a medium severity vulnerability due to its impact on user data and system integrity.
2
How does CVE-2025-48205 affect TYPO3 users?
CVE-2025-48205 exposes users to Insecure Direct Object Reference, potentially allowing unauthorized access to user data.
3
How do I fix CVE-2025-48205?
To fix CVE-2025-48205, update the sr_feuser_register extension to version 12.4.9 or later.
4
What versions of TYPO3 are vulnerable to CVE-2025-48205?
All versions of TYPO3 sr_feuser_register extension up to 12.4.8 are vulnerable to CVE-2025-48205.
5
What are the potential risks of CVE-2025-48205?
The risks of CVE-2025-48205 include unauthorized access to sensitive user information and potential data breaches.