Total vulnerabilities in the database
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.
Software | From | Fixed in |
---|---|---|
![]() |
5.0.0-beta.1 | 5.2.3 |
craftcms / craft_cms | 5.0.1 | 5.2.3 |
craftcms / craft_cms | 5.0.0-beta1 | 5.0.0-beta1.x |
craftcms / craft_cms | 5.0.0-beta10 | 5.0.0-beta10.x |
craftcms / craft_cms | 5.0.0-beta11 | 5.0.0-beta11.x |
craftcms / craft_cms | 5.0.0-beta2 | 5.0.0-beta2.x |
craftcms / craft_cms | 5.0.0-beta3 | 5.0.0-beta3.x |
craftcms / craft_cms | 5.0.0-beta4 | 5.0.0-beta4.x |
craftcms / craft_cms | 5.0.0-beta5 | 5.0.0-beta5.x |
craftcms / craft_cms | 5.0.0-beta6 | 5.0.0-beta6.x |
craftcms / craft_cms | 5.0.0-beta7 | 5.0.0-beta7.x |
craftcms / craft_cms | 5.0.0-beta8 | 5.0.0-beta8.x |
craftcms / craft_cms | 5.0.0-beta9 | 5.0.0-beta9.x |
craftcms / craft_cms | 5.0.0-rc1 | 5.0.0-rc1.x |