Executive brief
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing
Affected products
- packagist:https://packages.drupal.org/8 drupal/tfa
- Packagist drupal/tfa
Junglewise Threat Intelligence
CVE-2025-31694 · Severity: low · CVSS 3.1 · Published 2025-04-01
Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Tfa. Vendors: Packagist:Https://Packages.Drupal.Org/8, Packagist.
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing