CVE-2025-25227

Vulnérabilités

CVE-2025-25227

Joomla CMS Multi-Factor Authentication Bypass

HIGH Joomla CMS

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

7.5 Élevée · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Score retenu : GitHub Advisories

SourceSévérité d'origineCVSS
GitHub Advisorieshigh 7.5 (v3.1)
OSVHIGH 7.5 (v3.1) calculé
CERT-FR (ANSSI)— —
Produit
Joomla CMS
Corrigée dans
5.2.6, 4.4.13
Publiée
08/04/2025
Modifiée
05/06/2025
CWE
CWE-287
  • 5.0.0 – 5.2.6 (exclue)
  • 4.0.0 – 4.4.13 (exclue)

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Source ajoutée : certfr26/09/2026 09:28 UTC
  2. Source ajoutée : osv26/09/2026 09:27 UTC
  3. Détectée via github26/09/2026 09:27 UTC