CVE Vulnerabilities

CVE-2025-31694

Authentication Bypass Using an Alternate Path or Channel

Published: Mar 31, 2025 | Modified: Sep 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Two-factor_authenticationTwo-factor_authentication_project*8.x-1.10 (excluding)

Potential Mitigations

References