VYPR
High severityNVD Advisory· Published Apr 8, 2025· Updated Apr 21, 2025

[20250402] - Joomla Core - MFA Authentication Bypass

CVE-2025-25227

Description

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
joomla/joomla-cmsPackagist
>= 5.0.0, < 5.2.65.2.6
joomla/joomla-cmsPackagist
>= 4.0.0, < 4.4.134.4.13

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.