The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
{ "github_reviewed_at": "2024-06-06T19:13:50Z", "severity": "LOW", "nvd_published_at": "2024-06-06T11:15:49Z", "github_reviewed": true, "cwe_ids": [ "CWE-200", "CWE-522" ] }