reint_downloadmanager TYPO3 Extension is susceptible to Insecure Direct Object Reference
Moderate severity
GitHub Reviewed
Published
May 21, 2025
to the GitHub Advisory Database
•
Updated May 21, 2025
Package
Affected versions
>= 5.0.0, < 5.0.1
< 4.0.2
Patched versions
5.0.1
4.0.2
Description
Published by the National Vulnerability Database
May 21, 2025
Published to the GitHub Advisory Database
May 21, 2025
Reviewed
May 21, 2025
Last updated
May 21, 2025
Insecure Direct Object Reference in the reint_downloadmanager TYPO3 extension allows remote attackers to read arbitrary files via the downloaduid parameter in the downloadAction.
References