6.5

CVE-2024-5658

Exploit

CraftCMS Plugin - Two-Factor Authentication - TOTP Token Stays Valid After Use

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Born05Two-factor Authentication SwPlatformcraftcms Version < 3.3.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.435
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a 4.8 1.2 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-303 Incorrect Implementation of Authentication Algorithm

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

https://github.com/born05/craft-twofactorauthentication/releases/tag/3.3.4
Release Notes
https://plugins.craftcms.com/two-factor-authentication?craft4
Product
http://www.openwall.com/lists/oss-security/2024/06/06/2
Third Party Advisory
Exploit
Mailing List
https://github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20240202-02_CraftCMS_Plugin_Two-Factor_Authentication_TOTP_Valid_After_Use
Third Party Advisory
Exploit