First published: Tue Apr 08 2025(Updated: )
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | ||
composer/joomla/joomla-cms | >=4.0.0<4.4.13 | 4.4.13 |
composer/joomla/joomla-cms | >=5.0.0<5.2.6 | 5.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25227 is rated as a high-severity vulnerability due to its potential to bypass two-factor authentication checks.
To fix CVE-2025-25227, update your Joomla Core to the latest patched version provided by the Joomla security team.
CVE-2025-25227 allows attackers to circumvent two-factor authentication, compromising the security of user accounts.
Any version of Joomla Core that has not applied the latest security patches is considered vulnerable to CVE-2025-25227.
In addition to updating Joomla, consider implementing additional security measures like stronger password policies and user training.