Summary
Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted.
ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mautic
Mautic mautic |
|
| Vendors & Products |
Mautic
Mautic mautic |
Tue, 02 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution. | |
| Title | GrapesJsBuilder File Upload allows all file uploads | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Mautic
Published: 2025-12-02T16:54:39.986Z
Updated: 2025-12-02T17:10:25.179Z
Reserved: 2025-12-01T15:20:24.945Z
Link: CVE-2025-13827
Updated: 2025-12-02T17:10:19.200Z
Status : Awaiting Analysis
Published: 2025-12-02T17:16:03.847
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13827
No data.
ReportizFlow