Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13828

Опубликовано: 02 дек. 2025
Источник: nvd
EPSS Низкий

Описание

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

EPSS

Процентиль: 15%
0.0005
Низкий

Дефекты

CWE-862

Связанные уязвимости

github
2 месяца назад

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

EPSS

Процентиль: 15%
0.0005
Низкий

Дефекты

CWE-862