Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9018 | Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing |
Github GHSA |
GHSA-hf6c-fgp3-jfch | Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-023 |
|
Tue, 02 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Two-factor Authentication Project
Two-factor Authentication Project two-factor Authentication |
|
| CPEs | cpe:2.3:a:two-factor_authentication_project:two-factor_authentication:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Two-factor Authentication Project
Two-factor Authentication Project two-factor Authentication |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 |
Tue, 01 Apr 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-288 |
Mon, 31 Mar 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0. | |
| Title | Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2025-023 | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:19:38.757Z
Reserved: 2025-03-31T21:30:25.064Z
Link: CVE-2025-31694
Updated: 2025-04-29T15:19:19.150Z
Status : Analyzed
Published: 2025-03-31T22:15:22.100
Modified: 2025-09-02T18:35:00.753
Link: CVE-2025-31694
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA