Description
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.
Problem types
CWE-267 Privilege Defined With Unsafe Actions
Product status
0.0.0 (semver) before 1.11.0
Credits
Conrad Lara (cmlara)
Conrad Lara (cmlara)
cilefen (cilefen)
Dan Smith (galooph)
Greg Knaddison (greggles)
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-085