CVE-2025-47710: Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-056
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47710?
CVE-2025-47710 is considered a critical vulnerability due to the potential for authentication bypass.
How do I fix CVE-2025-47710?
To fix CVE-2025-47710, upgrade Drupal Enterprise MFA - TFA to version 4.7.0 or later, or to version 5.2.0 or later.
Which versions of Drupal Enterprise MFA - TFA are affected by CVE-2025-47710?
CVE-2025-47710 affects versions of Drupal Enterprise MFA - TFA prior to 4.7.0 and from 5.0.0 to 5.2.0.
What type of vulnerability is CVE-2025-47710?
CVE-2025-47710 is classified as an Authentication Bypass Using an Alternate Path or Channel vulnerability.
Can CVE-2025-47710 be exploited remotely?
Yes, CVE-2025-47710 can be exploited remotely, allowing unauthorized access to affected systems.