#VU109591 Authorization bypass through user-controlled key in Frontend User Registration - CVE-2025-48205
Published: May 21, 2025
Frontend User Registration
TYPO3
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension does not verify if a specified file identifier is authorized for download. A remote attacker can disclose and download arbitrary files without further authentication, leading to Insecure Direct Object Reference (IDOR) issue.