Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-5657

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.6%
CVSS Severity
CVSS v3 Score 3.7
Products affected by CVE-2024-5657


Contact Us

Shodan ® - All rights reserved