The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
{ "nvd_published_at": "2024-06-06T11:15:49Z", "cwe_ids": [ "CWE-200", "CWE-522" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-06-06T19:13:50Z" }