CVE Vulnerabilities

CVE-2025-31694

Authentication Bypass Using an Alternate Path or Channel

Published: Mar 31, 2025 | Modified: Sep 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Two-factor_authentication Two-factor_authentication_project * 8.x-1.10 (excluding)

Potential Mitigations

References