{"id":"GHSA-6423-85cc-8gf6","summary":"Joomla CMS Multi-Factor Authentication Bypass","details":"Insufficient state checks lead to a vector that allows to bypass 2FA checks.","aliases":["BIT-joomla-2025-25227","CVE-2025-25227"],"modified":"2025-06-05T06:44:17.939135Z","published":"2025-04-08T18:34:43Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-04-09T13:08:22Z","nvd_published_at":"2025-04-08T17:15:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25227"},{"type":"WEB","url":"https://developer.joomla.org/security-centre/964-20250402-core-mfa-authentication-bypass.html"},{"type":"PACKAGE","url":"https://github.com/joomla/joomla-cms"}],"affected":[{"package":{"name":"joomla/joomla-cms","ecosystem":"Packagist","purl":"pkg:composer/joomla/joomla-cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.2.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json"}},{"package":{"name":"joomla/joomla-cms","ecosystem":"Packagist","purl":"pkg:composer/joomla/joomla-cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.4.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}