The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1903 The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
Github GHSA Github GHSA GHSA-3p4x-grpm-xw58 Password hash exposed in CraftCMS two factor authentication plugin
Fixes

Solution

Update to version 3.3.4 or later.


Workaround

No workaround given by the vendor.

History

Wed, 03 Sep 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-499

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00069}

epss

{'score': 0.00125}


cve-icon MITRE

Status: PUBLISHED

Assigner: sba-research

Published:

Updated: 2025-09-03T07:13:32.028Z

Reserved: 2024-06-05T16:36:00.302Z

Link: CVE-2024-5657

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.699Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T11:15:49.277

Modified: 2025-09-03T08:15:31.270

Link: CVE-2024-5657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.