First published: Mon Mar 31 2025(Updated: )
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Email TFA | <2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31676 has been classified as a weak authentication vulnerability, which can lead to brute force attacks.
To fix CVE-2025-31676, you should upgrade Drupal Email TFA to version 2.0.3 or later.
CVE-2025-31676 affects all versions of Drupal Email TFA prior to 2.0.3.
CVE-2025-31676 allows attackers to perform brute force attacks, potentially compromising user accounts on your Drupal site.
There are no specific workarounds for CVE-2025-31676; upgrading to a fixed version is the recommended solution.