CVE-2025-47709: Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-055
Published May 14, 2025
·Updated
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Affected Software
3 affected components
Drupal Enterprise MFA - TFA for Drupal>0.0.0, <4.7.0, >5.0.0, <5.2.0
miniOrange Miniorange 2fa Drupal>=5.0.0<5.2.0
miniOrange Miniorange 2fa Drupal>=7.x-2.16<8.x-4.7
Event History
May 14, 2025
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Dec 28, 57353
Event
via FIRST·08:29 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-47709?
CVE-2025-47709 is classified as a missing authorization vulnerability which can lead to forceful browsing.
2
How do I fix CVE-2025-47709?
To fix CVE-2025-47709, upgrade your Drupal Enterprise MFA - TFA for Drupal to version 4.7.0 or 5.2.0 or later.
3
What versions are affected by CVE-2025-47709?
CVE-2025-47709 affects Drupal Enterprise MFA - TFA for Drupal versions before 4.7.0 and from 5.0.0 to before 5.2.0.
4
What is forceful browsing in the context of CVE-2025-47709?
Forceful browsing refers to unauthorized access to resources by guessing URLs or modifying requests.
5
Which Drupal products are impacted by CVE-2025-47709?
CVE-2025-47709 impacts the Drupal Enterprise MFA - TFA for Drupal products.