CVE-2024-5657CWE-499

CraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure

Low · published June 6, 2024

CVSS v3.1
3.7
EPSS
1%
Percentile
55.3
In the wild
Unconfirmed
What it is

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00832 · 55.3th percentile
Weakness
CWE-499 · Serializable Class Containing Sensitive Data
Published
2024-06-06T10:29Z
EPSS history
Timeline
  • 06 JUN 10:29Z
    CraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure
    cvelistv5