CVE-2025-47706
14.05.2025, 17:15
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.Enginsight
Vendor | Product | Version |
---|---|---|
miniorange | miniorange_2fa | 5.0.0 ≤ 𝑥 < 5.2.0 |
miniorange | miniorange_2fa | 7.x-2.16 ≤ 𝑥 < 8.x-4.7 |
𝑥
= Vulnerable software versions