CVE-2025-13828: Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Summary
A non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
Impact
A low-privileged user of the platform can install malicious code to obtain higher privileges.
Other sources
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13828?
CVE-2025-13828 is considered a low-severity vulnerability affecting Mautic.
How do I fix CVE-2025-13828?
To mitigate CVE-2025-13828, ensure that the enable composer based update flag is ticked in the update settings.
Who is affected by CVE-2025-13828?
CVE-2025-13828 affects users of Mautic who have granted low-privileged users access to the composer functionality.
What is the impact of CVE-2025-13828?
The impact of CVE-2025-13828 is that low-privileged users can install and remove arbitrary packages, potentially introducing malicious code.
Is there a workaround for CVE-2025-13828?
As a workaround for CVE-2025-13828, restrict access to composer functionalities for low-privileged users.