← Back

CVE-2024-47059

nvd nist
Published: Sep 18, 2024Modified: Feb 27, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification. This difference could be used to perform username enumeration.

Affected (1)

Products: Acquia: Mautic
1 product
Mautic
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.1.0

References (1)

Timeline

No history available yet.