Beveiligingsadvies

CVE-2024-5657

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-06 10:29:40
Laatst bijgewerkt 2025-09-03 07:13:32
Toegewezen door sba-research
CVSS-score 3.7
Status PUBLISHED

Beschrijving

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.