CVE Vulnerabilities

CVE-2025-47707

Authentication Bypass Using an Alternate Path or Channel

Published: May 14, 2025 | Modified: Jun 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Miniorange_2fa Miniorange 5.0.0 (including) 5.2.0 (excluding)
Miniorange_2fa Miniorange 7.x-2.16 (including) 8.x-4.7 (excluding)

Potential Mitigations

References