Логотип exploitDog
bind:CVE-2024-47057
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-47057

Количество 2

Количество 2

nvd логотип

CVE-2024-47057

8 месяцев назад

SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-424x-cxvh-wq9p

8 месяцев назад

Mautic allows user name enumeration due to response time difference on password reset form

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-47057

SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-424x-cxvh-wq9p

Mautic allows user name enumeration due to response time difference on password reset form

CVSS3: 5.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу