Vulnerability Details CVE-2024-41800
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.5%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2024-41800
-
cpe:2.3:a:craftcms:craft_cms:5.0.0
-
cpe:2.3:a:craftcms:craft_cms:5.0.1
-
cpe:2.3:a:craftcms:craft_cms:5.0.2
-
cpe:2.3:a:craftcms:craft_cms:5.0.3
-
cpe:2.3:a:craftcms:craft_cms:5.0.4
-
cpe:2.3:a:craftcms:craft_cms:5.0.5
-
cpe:2.3:a:craftcms:craft_cms:5.0.6
-
cpe:2.3:a:craftcms:craft_cms:5.1.0
-
cpe:2.3:a:craftcms:craft_cms:5.1.1
-
cpe:2.3:a:craftcms:craft_cms:5.1.10
-
cpe:2.3:a:craftcms:craft_cms:5.1.2
-
cpe:2.3:a:craftcms:craft_cms:5.1.3
-
cpe:2.3:a:craftcms:craft_cms:5.1.4
-
cpe:2.3:a:craftcms:craft_cms:5.1.5
-
cpe:2.3:a:craftcms:craft_cms:5.1.6
-
cpe:2.3:a:craftcms:craft_cms:5.1.7
-
cpe:2.3:a:craftcms:craft_cms:5.1.8
-
cpe:2.3:a:craftcms:craft_cms:5.1.9
-
cpe:2.3:a:craftcms:craft_cms:5.2.0
-
cpe:2.3:a:craftcms:craft_cms:5.2.1
-
cpe:2.3:a:craftcms:craft_cms:5.2.2