CVE Database
/

CVE-2025-13828

Back to search

CVE-2025-13828

Published: Dec 2, 2025

Modified: Dec 2, 2025

PUBLISHED

Description

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

VendorProductVersions

Mautic

Mautic

affected
<4.4.18, <5.2.9, <6.0.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now