HomeDefault status
unaffected
0.0.0 (semver) before 2.0.6
affected
Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.0.0 (semver) before 2.0.6
Credits
Pierre Rudloff (prudloff)
abdulaziz zaid
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Pierre Rudloff (prudloff)
References
www.drupal.org/sa-contrib-2025-115