High severityNVD Advisory· Published Dec 5, 2022· Updated Aug 3, 2024
CVE-2022-37783
CVE-2022-37783
Description
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corresponding HTML hidden field discloses the users' password hash in a masked manner, which can be decoded by using public functions of the YII framework.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
craftcms/cmsPackagist | >= 3.0.0, < 3.7.33 | 3.7.33 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-h972-v458-m892ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-37783ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/06/06/1ghsamailing-listWEB
- at-trustit.tuv.at/tuev-trust-it-cves/cve-disclosure-of-password-hashesghsaWEB
- cves.at/posts/cve-2022-37783/writeupghsaWEB
- at-trustit.tuv.at/tuev-trust-it-cves/cve-disclosure-of-password-hashes/mitre
- cves.at/posts/cve-2022-37783/writeup/mitre
News mentions
0No linked articles in our index yet.