The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
The code contains a class with sensitive data, but the class does not explicitly deny serialization. The data can be accessed by serializing the class through another class.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Two-factor_authentication | Born05 | 3.3.1 (including) | 3.3.4 (excluding) |