CVE-2025-48010

Published May 21, 2025

Last updated 17 days ago

Overview

Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
Source
mlhess@drupal.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.8
Impact score
2.5
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

mlhess@drupal.org
CWE-288

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.