Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fq7-c5m8-g86x

Опубликовано: 02 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9

Описание

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

Summary

A non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

Impact

A low-privileged user of the platform can install malicious code to obtain higher privileges.

Пакеты

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.4.18

4.4.18

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.2.9

5.2.9

Наименование

mautic/core

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.7

6.0.7

EPSS

Процентиль: 15%
0.0005
Низкий

9 Critical

CVSS4

Дефекты

CWE-284
CWE-862

Связанные уязвимости

nvd
2 месяца назад

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

EPSS

Процентиль: 15%
0.0005
Низкий

9 Critical

CVSS4

Дефекты

CWE-284
CWE-862