ummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack. MitigationPlease update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.
No configuration.
28 May 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-05-28 18:15
Updated : 2025-05-29 14:29
NVD link : CVE-2024-47057
Mitre link : CVE-2024-47057
CVE.ORG link : CVE-2024-47057
JSON object : View
No product.
Observable Discrepancy