CVE-2025-48010: One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-061
Published May 21, 2025
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
Affected Software
2 affected components
Drupal One Time Password>0.0.0, <1.3.0
One Time Password Project One Time Password Drupal>=8.x-1.0<8.x-1.3
Event History
May 21, 2025
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48010?
CVE-2025-48010 has a medium severity rating due to its potential for authentication bypass.
2
How do I fix CVE-2025-48010?
To fix CVE-2025-48010, upgrade Drupal One Time Password to version 1.3.0 or later.
3
What versions are affected by CVE-2025-48010?
CVE-2025-48010 affects versions of Drupal One Time Password from 0.0.0 up to, but not including, 1.3.0.
4
What vulnerability allows the bypass in CVE-2025-48010?
CVE-2025-48010 allows functionality bypass through an alternate path or channel in the authentication process.
5
Is there a workaround for CVE-2025-48010 before upgrading?
There is no official workaround for CVE-2025-48010; upgrading to the patched version is recommended.