CVE-2024-47053

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Feb 26, 2025
CWE ID 285

Summary

CVE-2024-47053 is an authorization vulnerability affecting Mautic's HTTP Basic Authentication implementation. This issue allows any authenticated user, regardless of assigned roles or permissions, to bypass intended access controls and gain unauthorized access to sensitive report data through the API. This vulnerability bypasses the "Reporting Permissions > View Own" and "Reporting Permissions > View Others" permissions, which are intended to restrict access to non-System Reports. This could potentially lead to confidential data exposure. Users are urged to apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share