THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2022-37783

Assigner:mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca)
Reserved:2022-08-08
Published:2022-12-05
Updated:2024-06-10

Description

All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corresponding HTML hidden field discloses the users' password hash in a masked manner, which can be decoded by using public functions of the YII framework.

References

https://at-trustit.tuv.at/tuev-trust-it-cves/cve-disclosure-of-password-hashes/

https://cves.at/posts/cve-2022-37783/writeup/

http://www.openwall.com/lists/oss-security/2024/06/06/1 ([oss-security] 20240606 [SBA-ADV-20240202-01] CVE-2024-5657: CraftCMS Plugin - Two-Factor Authentication 3.3.1 to 3.3.3 - Password Hash Disclosure) mailing-list

cve.org CVE-2022-37783

nvd.nist.gov CVE-2022-37783

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-37783