CVE-2025-47707: Enterprise MFA - TFA for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2025-053
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47707?
CVE-2025-47707 is a critical vulnerability that allows authentication bypass in Drupal's Enterprise MFA - TFA.
How does CVE-2025-47707 affect users?
CVE-2025-47707 can be exploited to gain unauthorized access to protected resources, potentially leading to data breaches.
How do I fix CVE-2025-47707?
To fix CVE-2025-47707, update your Enterprise MFA - TFA for Drupal to version 4.7.0 or 5.2.0 or later.
What versions of Drupal are affected by CVE-2025-47707?
CVE-2025-47707 affects Drupal Enterprise MFA - TFA versions prior to 4.7.0 and versions from 5.0.0 up to 5.2.0.
Can CVE-2025-47707 be exploited remotely?
Yes, CVE-2025-47707 can be exploited remotely by attackers to bypass authentication mechanisms.