HomeDefault status
unaffected
0.0.0 (semver) before 4.7.0
affected
5.0.0 (semver) before 5.2.0
affected
Description
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Problem types
Product status
0.0.0 (semver) before 4.7.0
5.0.0 (semver) before 5.2.0
Credits
Juraj Nemec (poker10)
Sudhanshu Dhage (sudhanshu0542)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-055