Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Craftcms
Craftcms craft Cms |
|
CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta10:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta11:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta5:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta6:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta7:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta8:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:beta9:*:*:*:*:*:* cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:* |
|
Vendors & Products |
Craftcms
Craftcms craft Cms |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-25T16:12:58.907Z
Updated: 2024-08-02T04:46:52.695Z
Reserved: 2024-07-22T13:57:37.135Z
Link: CVE-2024-41800
Vulnrichment
Updated: 2024-08-02T04:46:52.695Z
NVD
Status : Modified
Published: 2024-07-25T17:15:11.203
Modified: 2024-11-21T09:33:05.817
Link: CVE-2024-41800
Redhat
No data.