Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20698 | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0. |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-085 |
|
Thu, 04 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Two-factor Authentication Project
Two-factor Authentication Project two-factor Authentication |
|
| CPEs | cpe:2.3:a:two-factor_authentication_project:two-factor_authentication:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Two-factor Authentication Project
Two-factor Authentication Project two-factor Authentication |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 08 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0. | |
| Title | Two-factor Authentication (TFA) - Less critical - Access bypass - SA-CONTRIB-2025-085 | |
| Weaknesses | CWE-267 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-07-09T14:23:22.669Z
Reserved: 2025-07-02T16:07:06.376Z
Link: CVE-2025-7030
Updated: 2025-07-09T13:49:33.944Z
Status : Analyzed
Published: 2025-07-08T21:15:28.773
Modified: 2025-09-04T17:06:35.090
Link: CVE-2025-7030
No data.
OpenCVE Enrichment
Updated: 2025-07-13T22:31:26Z
EUVD