Intel

AIKIDO-2024-10138

craftcms/cms is vulnerable to Improper Authentication

Improper AuthenticationCVE-2024-41800 Published Jun 21, 2024

50

Medium Risk

This Affects:

phpcraftcms/cms
5.0.0 - 5.2.2
Fixed in 5.2.3
Are you affected? Scan for Free

TL;DR

Affected versions of craftcms/cms are vulnerable to insufficient expiration of TOTP codes, which allows an attacker to use expired tokens to pass TOTP authentication.

Who does this affect?

You are affected if you use a vulnerable version of craftcms/cms.

Background info

craftcms/cms is vulnerable to Improper Authentication in versions 5.0.0 - 5.2.2.

How to fix this

Upgrade craftcms/cms to a patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform