VYPR
Low severity3.7NVD Advisory· Published Jun 6, 2024· Updated Jun 17, 2026

CVE-2024-5657

CVE-2024-5657

Description

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
born05/craft-twofactorauthenticationPackagist
>= 3.3.1, < 3.3.43.3.4

Affected products

3

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.