Insecure Direct Object Reference in the reint_downloadmanager TYPO3 extension allows remote attackers to read arbitrary files via the downloaduid parameter in the downloadAction.
{
"cwe_ids": [
"CWE-425",
"CWE-639"
],
"github_reviewed": true,
"github_reviewed_at": "2025-05-21T18:22:06Z",
"nvd_published_at": "2025-05-21T16:15:33Z",
"severity": "MODERATE"
}