craftcms/cms is vulnerable to Improper Authentication
50
Medium Risk
Affected versions of craftcms/cms are vulnerable to insufficient expiration of TOTP codes, which allows an attacker to use expired tokens to pass TOTP authentication.
You are affected if you use a vulnerable version of craftcms/cms.
craftcms/cms is vulnerable to Improper Authentication in versions 5.0.0 - 5.2.2.
Upgrade craftcms/cms to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant