cbcvebase.
CVE-2024-41800
published 2024-07-25

CVE-2024-41800: Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit…

PriorityP342high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.43%
34.6th percentile
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.

Affected

4 ranges
VendorProductVersion rangeFixed in
craftcmscms
craftcmscms>= 5.0.0-beta.1 < 5.2.35.2.3
craftcmscraft_cms
craftcmscraft_cms>= 5.0.1 < 5.2.35.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.