Security Advisory
CVE-2024-5657
3.7
LOW
Vulnerability Description
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Published Date
June 6, 2024
Official Source
NIST NVD Advisory