Home

Description

SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.

PUBLISHED Reserved 2024-09-17 | Published 2025-05-28 | Updated 2025-05-29 | Assigner Mautic




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-203 Observable Discrepancy

Product status

Default status
unaffected

> 1.0 (semver) before < 6.0.2, < 5.2.6, < 4.4.16
affected

Credits

Tomasz Kowalczyk reporter

Patryk Gruszka remediation reviewer

Nick Vanpraet remediation reviewer

Tomasz Kowalczyk remediation developer

References

github.com/...mautic/security/advisories/GHSA-424x-cxvh-wq9p

cve.org (CVE-2024-47057)

nvd.nist.gov (CVE-2024-47057)

Download JSON