PT-2025-23116 · Mautic · Mautic
Nick Vanpraet
+2
·
Published
2025-05-28
·
Updated
2025-05-30
·
CVE-2024-47057
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mautic (affected versions not specified)
Description
A security issue exists in the "Forget your password" functionality of Mautic, allowing unauthenticated users to enumerate valid usernames through a timing-based attack. This is due to differences in response times for existing and non-existing users, combined with a lack of request limiting.
Recommendations
Update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mautic