{"data":{"id":"CVE-2025-25227","cve_id":"CVE-2025-25227","title":"Joomla CMS Multi-Factor Authentication Bypass","summary":"Joomla CMS Multi-Factor Authentication Bypass","severity":"HIGH","cvss":{"score":7.5,"version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","source":"github"},"published_at":"2025-04-08T18:34:43Z","modified_at":"2025-06-05T06:27:11.244829Z","withdrawn_at":null,"is_joomla":true,"is_joomla_core":true,"relevance":"certain","product":"Joomla CMS","extension":{"type":null,"name":null},"sources":["certfr","github","osv"],"source_count":3,"url":"https://cve.oyer.fr/cve/CVE-2025-25227","description":"Insufficient state checks lead to a vector that allows to bypass 2FA checks.","cwe":["CWE-287"],"affected":[{"package":"joomla/joomla-cms","product":"joomla/joomla-cms","vendor":null,"ecosystem":"composer","cpe":null,"version_start":"5.0.0","version_end":"5.2.6","version_end_inclusive":false,"fixed_version":"5.2.6","type":"core","source":"github"},{"package":"joomla/joomla-cms","product":"joomla/joomla-cms","vendor":null,"ecosystem":"composer","cpe":null,"version_start":"4.0.0","version_end":"4.4.13","version_end_inclusive":false,"fixed_version":"4.4.13","type":"core","source":"github"},{"package":null,"product":"Joomla!","vendor":"Joomla!","ecosystem":null,"cpe":null,"version_start":null,"version_end":null,"version_end_inclusive":false,"fixed_version":null,"type":"core","source":"certfr"}],"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25227","title":null,"source":"github"},{"url":"https://developer.joomla.org/security-centre/964-20250402-core-mfa-authentication-bypass.html","title":null,"source":"github"},{"url":"https://github.com/advisories/GHSA-6423-85cc-8gf6","title":null,"source":"github"},{"url":"https://github.com/joomla/joomla-cms","title":"PACKAGE","source":"osv"},{"url":"https://www.cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0296/","title":"CERT-FR","source":"certfr"}],"source_records":[{"source":"github","external_id":"GHSA-6423-85cc-8gf6","url":"https://github.com/advisories/GHSA-6423-85cc-8gf6","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","first_seen_at":"2026-09-26T09:27:38.247142Z","last_seen_at":"2026-09-26T09:27:38.247142Z"},{"source":"osv","external_id":"GHSA-6423-85cc-8gf6","url":"https://osv.dev/vulnerability/GHSA-6423-85cc-8gf6","severity":"HIGH","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvss_version":"3.1","first_seen_at":"2026-09-26T09:27:57.036136Z","last_seen_at":"2026-09-26T09:27:57.036136Z"},{"source":"certfr","external_id":"CERTFR-2025-AVI-0296:CVE-2025-25227","url":"https://www.cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0296/","severity":null,"cvss_score":null,"cvss_vector":null,"cvss_version":null,"first_seen_at":"2026-09-26T09:28:00.526658Z","last_seen_at":"2026-09-26T09:28:00.526658Z"}],"history":[{"at":"2026-09-26T09:28:00.526658Z","event":"source_added","source":"certfr","detail":"Source ajoutée : certfr"},{"at":"2026-09-26T09:27:57.036136Z","event":"source_added","source":"osv","detail":"Source ajoutée : osv"},{"at":"2026-09-26T09:27:38.247142Z","event":"created","source":"github","detail":"Détectée via github"}]}}
