Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.0.0 (semver) before 4.7.0
5.0.0 (semver) before 5.2.0
Credits
Conrad Lara (cmlara)
Sudhanshu Dhage (sudhanshu0542)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-056