CVE-2025-25227: [20250402] - Joomla Core - MFA Authentication Bypass
Published Apr 8, 2025
·Updated
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Affected Software
5 affected componentsFixes available
Joomla Joomla Core
composer/joomla/joomla-cms>=4.0.0<4.4.13
4.4.13
composer/joomla/joomla-cms>=5.0.0<5.2.6
5.2.6
Joomla Joomla\!>=4.0.0<4.4.13
Joomla Joomla\!>=5.0.0<5.2.6
Event History
Apr 8, 2025
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:34 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-25227?
CVE-2025-25227 is rated as a high-severity vulnerability due to its potential to bypass two-factor authentication checks.
2
How do I fix CVE-2025-25227?
To fix CVE-2025-25227, update your Joomla Core to the latest patched version provided by the Joomla security team.
3
What impact does CVE-2025-25227 have on my Joomla installation?
CVE-2025-25227 allows attackers to circumvent two-factor authentication, compromising the security of user accounts.
4
Is my version of Joomla affected by CVE-2025-25227?
Any version of Joomla Core that has not applied the latest security patches is considered vulnerable to CVE-2025-25227.
5
What protections should I implement against CVE-2025-25227?
In addition to updating Joomla, consider implementing additional security measures like stronger password policies and user training.