Intel

AIKIDO-2024-10138

craftcms/cms is vulnerable to Improper Authentication

Improper AuthenticationCVE-2024-41800 Published Jun 21, 2024

50

Medium Risk

This Affects:

phpcraftcms/cms
5.0.0 - 5.2.2
Fixed in 5.2.3
Are you affected? Scan for Free

TL;DR

Affected versions of craftcms/cms are vulnerable to insufficient expiration of TOTP codes, which allows an attacker to use expired tokens to pass TOTP authentication.

Who does this affect?

You are affected if you use a vulnerable version of craftcms/cms.

Background info

craftcms/cms is vulnerable to Improper Authentication in versions 5.0.0 - 5.2.2.

How to fix this

Upgrade craftcms/cms to a patch version.