CVE Vulnerabilities

CVE-2025-47707

Authentication Bypass Using an Alternate Path or Channel

Published: May 14, 2025 | Modified: Jun 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Miniorange_2faMiniorange5.0.0 (including)5.2.0 (excluding)
Miniorange_2faMiniorange7.x-2.16 (including)8.x-4.7 (excluding)

Potential Mitigations

References