CVE-2024-47057 Information
Description
SummaryThis advisory addresses a security vulnerability in Mautic related to the \Forget your password\ functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames.
User Enumeration via Timing Attack: A user enumeration vulnerability exists in the \Forget your password\ functionality. Differences in response times for existing and non-existing users combined with a lack of request limiting allow an attacker to determine the existence of usernames through a timing-based attack.
MitigationPlease update to a version that addresses this timing vulnerability where password reset responses are normalized to respond at the same time regardless of user existence.
Reference
https://github.com/mautic/mautic/security/advisories/GHSA-424x-cxvh-wq9p
Share on: