# Security vulnerability

**URL:** <https://forum.mautic.org/t/security-vulnerability/29493>\
**Category:** Mautic 4 Install/Upgrade Support\
**Tags:** community, governance, discussion\
**Created:** [September 30, 2023, 3:31am UTC](https://forum.mautic.org/t/security-vulnerability/29493 "2023-09-30T03:31:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![team](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@team](https://forum.mautic.org/u/team)\
**Post date:** [September 30, 2023, 3:31am UTC](https://forum.mautic.org/t/security-vulnerability/29493/1 "2023-09-30T03:31:46Z")

</div>

Hi everyone,

Is there a security vulnerability with Mautic? The local PHP file contains both my username and password and is located in a public HTML folder. You can find the Mautic root path here: `app/config/local.php`.

If so, what security procedures do you recommend, such as 2FA, plugin, etc.?"

Regards,  
Hal  
DevCEd Team

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [September 30, 2023, 8:13am UTC](https://forum.mautic.org/t/security-vulnerability/29493/2 "2023-09-30T08:13:55Z")

</div>

You need to store it somewhere.  
And that is not your username, but DB, and SMTP credentials.  
The .htaccess file should make sure the unwanted files are not accessable.

---

<div class="post-metadata">

**Author:** ![mzagmajster](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mzagmajster/32/687_2.png) [@mzagmajster](https://forum.mautic.org/u/mzagmajster)\
**Post date:** [September 30, 2023, 9:21am UTC](https://forum.mautic.org/t/security-vulnerability/29493/3 "2023-09-30T09:21:47Z")

</div>

Additionally you can store such data in env. variables on the server. This is just addition to what joejk have said.

Implementing this alone is not enough.

---

<div class="post-metadata">

**Author:** ![team](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@team](https://forum.mautic.org/u/team)\
**Post date:** [September 30, 2023, 1:23pm UTC](https://forum.mautic.org/t/security-vulnerability/29493/4 "2023-09-30T13:23:10Z")

</div>

Hi,

Can we bundle Google Firebase Authenticator with Mautic:

(1) Firebase Authentication

> **[Firebase Authentication](https://firebase.google.com/docs/auth)**
>
> Firebase Authentication lets you add an end-to-end identity solution to your app for easy user authentication, sign-in, and onboarding in just a few lines of code.

(2) How to Build Firebase Multifactor Authentication

[![](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/2X/0/0d1868cf3f54dfd66ec35c3fb73e48062c6da17b.jpeg "How to Build Firebase MultiFactor Authentication") ](https://www.youtube.com/watch?v=Py5K_rv1_3A)

Regards,  
Hal  
DevCED Team

---

<div class="post-metadata">

**Author:** ![mzagmajster](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mzagmajster/32/687_2.png) [@mzagmajster](https://forum.mautic.org/u/mzagmajster)\
**Post date:** [September 30, 2023, 1:44pm UTC](https://forum.mautic.org/t/security-vulnerability/29493/5 "2023-09-30T13:44:35Z")

</div>

Looks like we have symfony bundle for firebase: [GitHub - kreait/firebase-bundle: A Symfony Bundle for the Firebase PHP Admin SDK](https://github.com/kreait/firebase-bundle)

If we want to use the actively developed bundle, we have to wait until Mautic 5, it looks like it.

---

<div class="post-metadata">

**Author:** ![team](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@team](https://forum.mautic.org/u/team)\
**Post date:** [October 1, 2023, 5:36am UTC](https://forum.mautic.org/t/security-vulnerability/29493/6 "2023-10-01T05:36:04Z")

</div>

What is the difference between **[symfony bundle for firebase](https://github.com/kreait/firebase-bundle)** and the following:

To add Firebase Authentication OAuth 2.0 credential to Mautic 4.0, you can follow these steps:

1. Log in to your Firebase account and go to the “Project settings” page for your project with ID “gmail-mail-xxxx”.
2. Click on the “Service accounts” tab and then click on the “Generate new private key” button to download a JSON file containing your private key.
3. Copy the contents of the JSON file to your clipboard.
4. SSH into your Mautic server and navigate to the `app/config` directory.
5. Create a new file called `firebase_credentials.json` in the `app/config` directory and paste the contents of the JSON file into the new file.
6. In the Mautic dashboard, go to the “Plugins” section and click on the “Social” tab.
7. Click on the “Add new” button and select “Google” as the provider.
8. Enter a name for the provider and select “OAuth 2.0” as the authentication type.
9. In the “Client ID” field, enter the value of the “client\_id” field from the JSON file.
10. In the “Client secret” field, enter the value of the “private\_key” field from the JSON file.
11. In the “Scopes” field, enter “email” and “profile”.
12. Click on the “Save & Close” button to save the provider.

Once you have completed these steps, you should be able to use Firebase Authentication OAuth 2.0 to authenticate users in Mautic 4.0.

Regards,  
Hal  
DevCED Team

---

<div class="post-metadata">

**Author:** ![mzagmajster](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mzagmajster/32/687_2.png) [@mzagmajster](https://forum.mautic.org/u/mzagmajster)\
**Post date:** [October 1, 2023, 8:50am UTC](https://forum.mautic.org/t/security-vulnerability/29493/7 "2023-10-01T08:50:24Z")

</div>

I did not use firebase so far, so I am not sure.

> [@team](#):
>
> In the Mautic dashboard, go to the “Plugins” section and click on the “Social” tab.

What is meant by that? Do not understand this instruction.

Regards, M.

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [October 2, 2023, 10:55am UTC](https://forum.mautic.org/t/security-vulnerability/29493/8 "2023-10-02T10:55:51Z")

</div>

@team this is getting confusing. As @joeyk pointed out, the password in app/config/local.php file is not your user password but a database password.

It’s safer to store it in a PHP file than any .env, yaml, json or other text format because if you run Mautic, the idea is that PHP files are executables and if someone access the file then it will execute rather than print out its content.

And as pointed out already, there is .htaccess that will secure it for Apache.

Then you are suggesting Firebase authentication. That is for user authentication, not database authentication.

Users have passwords stored in the database. The password is encrypted by standard algorithms, using salt and all that. They are as secure as they can be. If you want to use another provider for authentication then go ahead, but I fear that you will be confusing others when you discuss it on a forum topic called “Security vulnerability”. It’s unrelated.
