CVE-2024-47059
MEDIUMMautic 5.1.0 - Username Enumeration via Weak Password Login Response
Title source: llmDescription
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification. This difference could be used to perform username enumeration.
References (1)
Core 1
Core References
Scores
CVSS v3
4.3
EPSS
0.0033
EPSS Percentile
24.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (2)
acquia/mautic
5.1.0
mautic/core
5.1.0 - 5.1.1Packagist
Published
Sep 18, 2024
Tracked Since
Feb 18, 2026