CVE-2024-37893

MEDIUM

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malic...

Affects 0 products across 1 vendor.

BCS3.71
CVSS 3.15.9
EPSS0.6%
Percentile45th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

CWE-288: CWE-288
Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-127 Directory Indexing
via CWE-288
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-288
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Firefly III, a free and open source personal finance manager, is vulnerable to an MFA bypass in its OAuth flow, allowing attackers to bypass multi-factor authentication and potentially gain unauthorized access to user data through password spraying.

BSID: BS-2024-GLOBAL-197591-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-37893?
Firefly III, a free and open source personal finance manager, is vulnerable to an MFA bypass in its OAuth flow, allowing attackers to bypass multi-factor authentication and potentially gain unauthorized access to user data through password spraying.
What is the CVSS score for CVE-2024-37893?
CVE-2024-37893 has CVSS 5.9 (Medium). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. EPSS: 0.6%.
Is CVE-2024-37893 actively exploited?
No confirmed active exploitation of CVE-2024-37893 as of 2026-05-30.
How do I remediate CVE-2024-37893?
Priority: HIGH.
What systems are affected by CVE-2024-37893?
CVE-2024-37893 affects: Firefly.
Vulnerability Details
CVE IDCVE-2024-37893
BSIDBS-2024-GLOBAL-197591-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Published2024-06-17
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use password spraying to gain access to Firefly III data using passwords stolen from other sources. As OAuth applications are easily enumerable using an incrementing id, an attacker could try sign an OAuth application up to a users profile quite easily if they have created one. The attacker would also need to know the victims username and password. This problem has been patched in Firefly III v6.1.17 and up. Users are advised to upgrade. Users unable to upgrade should Use a unique password for their Firefly III instance and store their password securely, i.e. in a password manager.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability lies in the OAuth flow of Firefly III, where an attacker can bypass the multi-factor authentication (MFA) check. This enables the attacker to use password spraying techniques with stolen passwords from other sources to gain access to user accounts.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Firefly —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 768 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashd54cf24880b236ba00564093f7d3390c9c025ce826a7ea76e8fd59788dc6936eff5dba9fccfbf91348a9e7f0d1dedff9102339dff5006bd8c39caeebbd834136
Related CVEs affecting Firefly
CVE-2007-2456 7.5 Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow re... CVE-2007-2460 7.5 PHP remote file inclusion vulnerability in modules/admin/include/config.php i... CVE-2007-5825 7.5 Format string vulnerability in the ws_addarg function in webserver.c in mt-da... CVE-2007-5824 7.1 webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remo...
View all Firefly CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →