Логотип exploitDog
bind:CVE-2025-13828
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13828

Количество 2

Количество 2

nvd логотип

CVE-2025-13828

2 месяца назад

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

EPSS: Низкий
github логотип

GHSA-3fq7-c5m8-g86x

2 месяца назад

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13828

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

0%
Низкий
2 месяца назад
github логотип
GHSA-3fq7-c5m8-g86x

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

0%
Низкий
2 месяца назад

Уязвимостей на страницу