CVE-2025-31676

April 1, 2025, 8:26 p.m.

None
No Score

Description

Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.

Product(s) Impacted

Vendor Product Versions
Drupal
  • Email Tfa
  • 0.0.0-2.0.3

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-1390
Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a drupal email_tfa 0.0.0-2.0.3 / / / / / / /

Timeline

Published: March 31, 2025, 10:15 p.m.
Last Modified: April 1, 2025, 8:26 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

mlhess@drupal.org

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.