PT-2025-8691 · Mautic · Mautic

John Linhart

+3

·

Published

2025-02-26

·

Updated

2025-02-26

·

CVE-2024-47053

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mautic (affected versions not specified)
Description The issue concerns an authorization flaw in Mautic's HTTP Basic Authentication implementation, allowing unauthorized access to sensitive report data. Specifically, an improper authorization flaw exists in Mautic's API Authorization implementation, enabling any authenticated user to access all reports and their associated data via the API, bypassing intended access controls.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-47053
GHSA-8XV7-G2Q3-FQGC

Affected Products

Mautic