CVE-2024-48572

A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs due to insufficiently validated user input being processed as a regular expression, which is then matched against email addresses to find duplicate entries.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:aquila-cms:aquilacms:*:*:*:*:*:*:*:*

History

22 Apr 2025, 20:23

Type Values Removed Values Added
First Time Aquila-cms
Aquila-cms aquilacms
References () https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2024-48572 - () https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2024-48572 - Third Party Advisory
CPE cpe:2.3:a:aquila-cms:aquilacms:*:*:*:*:*:*:*:*

14 Mar 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

30 Oct 2024, 15:35

Type Values Removed Values Added
CWE CWE-276
Summary
  • (es) Una vulnerabilidad de enumeración de usuarios en AquilaCMS 1.409.20 y versiones anteriores permite a atacantes no autenticados obtener direcciones de correo electrónico a través de la función "Agregar un usuario". La vulnerabilidad se produce debido a que la entrada de usuario no validada de forma suficiente se procesa como una expresión regular, que luego se compara con las direcciones de correo electrónico para encontrar entradas duplicadas.

29 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 22:15

Updated : 2025-04-22 20:23


NVD link : CVE-2024-48572

Mitre link : CVE-2024-48572

CVE.ORG link : CVE-2024-48572


JSON object : View

Products Affected

aquila-cms

  • aquilacms
CWE
CWE-276

Incorrect Default Permissions