ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3fq7-c5m8-g86x | Mautic user without privileged access to the Marketplace can install and uninstall composer packages |
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mautic
Mautic mautic |
|
| Vendors & Products |
Mautic
Mautic mautic |
Tue, 02 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. | |
| Title | Mautic user without privileged access to the Marketplace can install and uninstall composer packages | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2025-12-02T17:12:20.703Z
Reserved: 2025-12-01T15:20:25.618Z
Link: CVE-2025-13828
Updated: 2025-12-02T17:12:06.655Z
Status : Deferred
Published: 2025-12-02T17:16:04.080
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13828
No data.
OpenCVE Enrichment
Updated: 2025-12-03T12:10:08Z
Github GHSA