CVE-2024-47059
Estado: AnalizadaMedia (4.3)—
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak.
However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification.
This difference could be used to perform username enumeration.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-47059",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-47059",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-25T20:45:37.083409Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@mautic.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@mautic.org",
"affectedData": [
{
"repo": "https://github.com/mautic/mautic",
"vendor": "Mautic",
"product": "Mautic",
"versions": [
{
"status": "affected",
"version": ">= 5.1.0",
"lessThan": "< 5.1.1",
"versionType": "semver"
}
],
"packageName": "mautic/core",
"collectionURL": "https://packagist.org",
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:mautic:mautic:*:*:*:*:*:*:*:*"
],
"vendor": "mautic",
"product": "mautic",
"versions": [
{
"status": "affected",
"version": "5.1.0",
"lessThan": "5.1.1",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-09-18T22:15:04.650",
"references": [
{
"url": "https://github.com/mautic/mautic/security/advisories/GHSA-8vff-35qm-qjvv",
"tags": [
"Vendor Advisory"
],
"source": "security@mautic.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@mautic.org",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak.\n\nHowever when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification.\n\nThis difference could be used to perform username enumeration."
},
{
"lang": "es",
"value": "Al iniciar sesión con el nombre de usuario correcto y una contraseña débil incorrecta, el usuario recibe una notificación que indica que su contraseña es demasiado débil. Sin embargo, cuando se proporciona un nombre de usuario incorrecto junto con una contraseña débil, la aplicación responde con una notificación de \"Credenciales no válidas\". Esta diferencia se puede utilizar para realizar la enumeración de nombres de usuario."
}
],
"lastModified": "2026-06-17T07:56:28.153",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:acquia:mautic:5.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "218C24B5-AAED-49DE-BD4D-DA7B37D55744"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@mautic.org"
}