CVE-2025-48011: One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-062
Published May 21, 2025
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
Affected Software
2 affected components
Drupal One Time Password>0.0.0, <1.3.0
One Time Password Project One Time Password Drupal>=8.x-1.0<8.x-1.3
Event History
May 21, 2025
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48011?
CVE-2025-48011 is rated as a critical vulnerability due to its potential to bypass authentication.
2
How do I fix CVE-2025-48011?
To fix CVE-2025-48011, upgrade the Drupal One Time Password module to version 1.3.0 or later.
3
Which versions of Drupal One Time Password are affected by CVE-2025-48011?
CVE-2025-48011 affects versions of Drupal One Time Password from 0.0.0 up to but not including 1.3.0.
4
What type of vulnerability is CVE-2025-48011?
CVE-2025-48011 is an Authentication Bypass vulnerability that allows users to bypass security measures.
5
Is there a workaround for CVE-2025-48011?
There is no known workaround for CVE-2025-48011; updating to the latest version is the recommended action.