The module enables you to add second-factor authentication in addition to the default Drupal login.
The module doesn't sufficiently protect certain routes from Cross Site Request Forgery (CSRF) attacks.
{ "constraint": "<4.7.0" }
{ "constraint": ">=5.0.1 <5.2.0" }
"<4.7.0 || >=5.0.1 <5.2.0"
true
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/miniorange_2fa/DRUPAL-CONTRIB-2025-054.json"