GHSA-cvgc-mx2w-h3w8

Suggest an improvement
Source
https://github.com/advisories/GHSA-cvgc-mx2w-h3w8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-cvgc-mx2w-h3w8/GHSA-cvgc-mx2w-h3w8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cvgc-mx2w-h3w8
Aliases
  • CVE-2025-48205
Published
2025-05-21T18:33:30Z
Modified
2025-05-21T20:42:13Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object Reference
Details

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference. This allows attackers to read arbitrary files.

Database specific
{
    "cwe_ids": [
        "CWE-425",
        "CWE-639"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-21T20:09:49Z",
    "nvd_published_at": "2025-05-21T16:15:32Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / sjbr/sr-feuser-register

Package

Name
sjbr/sr-feuser-register
Purl
pkg:composer/sjbr/sr-feuser-register

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
12.5.0

Affected versions

5.*
5.1.0
5.1.1
5.1.2
6.*
6.0.0
6.0.1
6.0.2
v7.*
v7.0.0
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v10.*
v10.4.0
v11.*
v11.5.0
v11.5.1
v11.5.2
v11.5.3
v11.5.4
v11.5.5
v12.*
v12.4.1
v12.4.2
v12.4.3
v12.4.4
v12.4.5
v12.4.6
v12.4.7
v12.4.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-cvgc-mx2w-h3w8/GHSA-cvgc-mx2w-h3w8.json"