Back

HIGH

CraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure

Published Jun 6, 2024

Description

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

Affected products

Remediation

Vendor solution

Update to version 3.3.4 or later.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sba-research
Published Jun 6, 2024
Updated Sep 3, 2025
Reserved Jun 5, 2024
CISA Vulnrichment
Updated Jun 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a
GHSA-3P4X-GRPM-XW58