CVE-2024-47059: Acquia Mautic
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an incorrect username is provided alongside with a weak password, the application responds with ’Invalid credentials’ notification. This difference could be used to perform username enumeration.
Affected products
- Acquia Mautic: version 5.1.0 only
Published 2024-09-18. Last modified 2026-06-17.