CVE-2024-5657
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Scoring
- Severity
- LOW
- CVSS base score
- 3.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.83%
- CWE
- CWE-499
- Published
- 2024-06-06
- Last modified
- 2026-03-13
Affected products
- Born05 CraftCMS Plugin - Two-Factor Authentication
Weakness type
Related vulnerabilities
- CVE-2022-39309 — GoCD server secret encryption/decryption key leaked to agents during material serialization