Intel

AIKIDO-2025-10469

drupal/tfa is vulnerable to Improper Privilege Management

Improper Privilege ManagementCVE-2025-7030 Published Jul 17, 2025

60

Medium Risk

This Affects:

PHPdrupal/tfa
0.0.0 - 1.10.0
Fixed in 1.11.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable due to incorrectly configured access control levels. The module does not adequately prevent privileged users from viewing the recovery codes of other users. This issue is partially mitigated by the requirement that an attacker must possess a role with the "Administer TFA for other users" permission.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/tfa is vulnerable to Improper Privilege Management in versions 0.0.0 - 1.10.0.

How to fix this

Upgrade the drupal/tfa library to the patch version.