VYPR

Two Factor Authentication

by Born05

Source repositories

CVEs (2)

  • CVE-2024-5658MedJun 6, 2024
    risk 0.24cvss 4.8epss 0.01

    The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

  • CVE-2024-5657LowJun 6, 2024
    risk 0.17cvss 3.7epss 0.01

    The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.