CVE-2024-47057 Information

Description

SummaryThis advisory addresses a security vulnerability in Mautic related to the \Forget your password\ functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames.

User Enumeration via Timing Attack: A user enumeration vulnerability exists in the \Forget your password\ functionality. Differences in response times for existing and non-existing users combined with a lack of request limiting allow an attacker to determine the existence of usernames through a timing-based attack.

MitigationPlease update to a version that addresses this timing vulnerability where password reset responses are normalized to respond at the same time regardless of user existence.

Reference

https://github.com/mautic/mautic/security/advisories/GHSA-424x-cxvh-wq9p

Share on: