Описание
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Ссылки
- ExploitMailing ListThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
- Product
- ExploitMailing ListThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия от 3.3.1 (включая) до 3.3.4 (исключая)
cpe:2.3:a:born05:two-factor_authentication:*:*:*:*:*:craftcms:*:*
EPSS
Процентиль: 43%
0.00205
Низкий
3.7 Low
CVSS3
8.1 High
CVSS3
Дефекты
CWE-499
CWE-522
Связанные уязвимости
CVSS3: 3.7
github
больше 1 года назад
Password hash exposed in CraftCMS two factor authentication plugin
EPSS
Процентиль: 43%
0.00205
Низкий
3.7 Low
CVSS3
8.1 High
CVSS3
Дефекты
CWE-499
CWE-522