Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
2025-05-14T17:15:49.963
2025-06-10T15:25:56.740
Analyzed
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | miniorange | miniorange_2fa | < 5.2.0 | Yes |
| Application | miniorange | miniorange_2fa | < 8.x-4.7 | Yes |