Description
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Published: 2024-06-06
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update to version 3.3.4 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1903 The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Github GHSA Github GHSA GHSA-3p4x-grpm-xw58 Password hash exposed in CraftCMS two factor authentication plugin
History

Wed, 03 Sep 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-499

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00069}

epss

{'score': 0.00125}


Subscriptions

Born05 Two-factor Authentication
cve-icon MITRE

Status: PUBLISHED

Assigner: sba-research

Published:

Updated: 2025-09-03T07:13:32.028Z

Reserved: 2024-06-05T16:36:00.302Z

Link: CVE-2024-5657

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.699Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T11:15:49.277

Modified: 2025-09-03T08:15:31.270

Link: CVE-2024-5657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses