Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
Upgrade to 2.12.0 or later.
None.
If you have any questions or comments about this advisory: * Email us at security@mautic.org
{ "nvd_published_at": "2018-01-03T17:29:00Z", "cwe_ids": [ "CWE-287" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-01-19T21:13:44Z" }