CVE-2024-47059

Source
https://cve.org/CVERecord?id=CVE-2024-47059
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47059.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-47059
Aliases
Published
2024-09-18T21:19:26Z
Modified
2026-08-12T03:51:20Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Users enumeration - weak password login
Details

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak.

However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification.

This difference could be used to perform username enumeration.

Database specific
{
    "cna_assigner": "Mautic",
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47059.json"
}
References

Affected packages

Git / github.com/mautic/mautic

Affected ranges

Type
GIT
Repo
https://github.com/mautic/mautic
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:acquia:mautic:5.1.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": ">= 5.1.0"
        },
        {
            "fixed": "< 5.1.1"
        },
        {
            "introduced": "5.1.0"
        },
        {
            "last_affected": "5.1.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

5.*
5.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47059.json"