CVE-2024-5658

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

Credits

Fabian Funder (SBA Research)
Jakob Pachmann (SBA Research)

References