HomeDefault status
unaffected
0.0.0 (semver) before 4.7.0
affected
5.0.0 (semver) before 5.2.0
affected
Description
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
0.0.0 (semver) before 4.7.0
5.0.0 (semver) before 5.2.0
Credits
Juraj Nemec (poker10)
Sudhanshu Dhage (sudhanshu0542)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-054