CVE Feed

    Dashboard / CVE / CVE-2024-2731

    CVE-2024-2731

    Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive information such as company names, users' names and surnames, stage names, and monitoring campaigns and their descriptions. In addition, unprivileged users can see and edit the descriptions of tags. At the time of publication of the CVE no patch is available.

    Published:Apr 10, 2024
    Last Modified:Apr 15, 2026
    EPS:Apr 10, 2024
    EPSS Score:0.00155
    CVSS Score:5.4

    Affected Products

    Vendor
    Mautic
    Product
    Mautic

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High