Description
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.3.4 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1994 | The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. |
Github GHSA |
GHSA-96qm-hwhp-2rm8 | Improper Authentication in CraftCMS two factor authentication plugin |
References
History
Wed, 03 Sep 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-303 |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Born05 craft Cms
|
|
| CPEs | cpe:2.3:a:born05:craft_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Born05 craft Cms
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2025-09-03T07:08:56.470Z
Reserved: 2024-06-05T16:36:00.494Z
Link: CVE-2024-5658
Updated: 2024-08-01T21:18:06.856Z
Status : Modified
Published: 2024-06-06T11:15:49.573
Modified: 2025-09-03T07:15:33.393
Link: CVE-2024-5658
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA