CVE-2024-47059

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
18/09/2024
Last modified:
27/02/2025

Description

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak.<br /> <br /> However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification.<br /> <br /> This difference could be used to perform username enumeration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:acquia:mautic:5.1.0:*:*:*:*:*:*:*