CVE-2024-41800
25.07.2024, 17:15
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.Enginsight
Vendor | Product | Version |
---|---|---|
craftcms | craft_cms | 5.0.1 ≤ 𝑥 < 5.2.3 |
craftcms | craft_cms | 5.0.0:beta1 |
craftcms | craft_cms | 5.0.0:beta10 |
craftcms | craft_cms | 5.0.0:beta11 |
craftcms | craft_cms | 5.0.0:beta2 |
craftcms | craft_cms | 5.0.0:beta3 |
craftcms | craft_cms | 5.0.0:beta4 |
craftcms | craft_cms | 5.0.0:beta5 |
craftcms | craft_cms | 5.0.0:beta6 |
craftcms | craft_cms | 5.0.0:beta7 |
craftcms | craft_cms | 5.0.0:beta8 |
craftcms | craft_cms | 5.0.0:beta9 |
craftcms | craft_cms | 5.0.0:rc1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References