First published: Mon Mar 31 2025(Updated: )
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing. This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Two-factor Authentication | <1.10.0 | |
composer/drupal/tfa | <1.10.0 | 1.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31694 is classified as a high-severity vulnerability due to its potential for unauthorized access.
To fix CVE-2025-31694, update Drupal Two-factor Authentication to version 1.10.0 or later.
CVE-2025-31694 allows for forceful browsing, which can lead to unauthorized access to user accounts.
Versions of Drupal Two-factor Authentication prior to 1.10.0 are affected by CVE-2025-31694.
Currently, there are no known workarounds for CVE-2025-31694 other than applying the update.