Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9jrw-jrrj-p6fr | Drupal Email TFA allows Functionality Bypass |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-115 |
|
Mon, 08 Dec 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Email Tfa Project
Email Tfa Project email Tfa |
|
| CPEs | cpe:2.3:a:email_tfa_project:email_tfa:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Email Tfa Project
Email Tfa Project email Tfa |
Thu, 20 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal drupal Drupal email Tfa |
|
| Vendors & Products |
Drupal
Drupal drupal Drupal email Tfa |
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6. | |
| Title | Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-115 | |
| Weaknesses | CWE-288 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-11-18T20:30:29.114Z
Reserved: 2025-11-05T17:03:15.328Z
Link: CVE-2025-12760
Updated: 2025-11-18T20:30:26.089Z
Status : Analyzed
Published: 2025-11-18T17:15:58.383
Modified: 2025-12-08T14:35:56.347
Link: CVE-2025-12760
No data.
OpenCVE Enrichment
Updated: 2025-11-20T10:30:47Z
Github GHSA