CVE-2022-37783
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corresponding HTML hidden field discloses the users' password hash in a masked manner, which can be decoded by using public functions of the YII framework.
Todas las versiones de Craft CMS entre 3.0.0 y 3.7.32 revelan hashes de contraseñas de usuarios que se autentican utilizando su dirección de correo electrónico o nombre de usuario en tokens Anti-CSRF. Craft CMS utiliza una cookie llamada CRAFT_CSRF_TOKEN y un campo oculto HTML llamado CRAFT_CSRF_TOKEN para evitar ataques de Cross Site Request Forgery. La cookie CRAFT_CSRF_TOKEN revela el hash de la contraseña sin codificarlo, mientras que el campo oculto HTML correspondiente revela el hash de la contraseña de los usuarios de manera enmascarada, que puede decodificarse mediante el uso de funciones públicas del framework YII.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-08-08 CVE Reserved
- 2022-12-05 CVE Published
- 2024-06-27 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2024/06/06/1 | Mailing List | |
https://cves.at/posts/cve-2022-37783/writeup |
URL | Date | SRC |
---|---|---|
https://at-trustit.tuv.at/tuev-trust-it-cves/cve-disclosure-of-password-hashes | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Craftcms Search vendor "Craftcms" | Craft Cms Search vendor "Craftcms" for product "Craft Cms" | >= 3.0.0 <= 3.7.32 Search vendor "Craftcms" for product "Craft Cms" and version " >= 3.0.0 <= 3.7.32" | - |
Affected
|