CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.7. Public exploit code or proof-of-concept references have been detected in its references. Exploitation may require the attacker to be authenticated.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2024-5657
Severity
LOW
CVSS
3.7
EPSS
0.83%
Original NVD Description
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Related CVEs
Other vulnerabilities affecting the same vendor(s)