CVE-2024-47059

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification. This difference could be used to perform username enumeration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:acquia:mautic:5.1.0:*:*:*:*:*:*:*

History

27 Feb 2025, 19:30

Type Values Removed Values Added
CPE cpe:2.3:a:acquia:mautic:5.1.0:*:*:*:*:*:*:*
First Time Acquia mautic
Acquia
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE NVD-CWE-Other
References () https://github.com/mautic/mautic/security/advisories/GHSA-8vff-35qm-qjvv - () https://github.com/mautic/mautic/security/advisories/GHSA-8vff-35qm-qjvv - Vendor Advisory

18 Sep 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 22:15

Updated : 2025-02-27 19:30


NVD link : CVE-2024-47059

Mitre link : CVE-2024-47059


JSON object : View

Products Affected

acquia

  • mautic