The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
| Software | From | Fixed in |
|---|---|---|
| born05 / two-factor_authentication | 3.3.1 | 3.3.4 |
born05 / craft-twofactorauthentication
|
3.3.1 | 3.3.4 |