Insecure Direct Object Reference in Mautic's Segment Cloning Functionality
CVE-2024-47055
What is CVE-2024-47055?
This advisory details a security vulnerability in Mautic associated with its segment cloning feature. The vulnerability arises from a missing authorization check within the cloneAction of the segment management functionality. This oversight allows any authenticated user to clone segments even if they do not possess the appropriate permissions to perform such actions. To mitigate this issue, it is essential to update to a newer version of Mautic, which incorporates the necessary authorization checks to ensure that only users with the correct permissions can clone segments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mautic > 5.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
