CVE-2025-48012: One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-063
Published May 21, 2025
·Updated
Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.
Affected Software
2 affected components
Drupal One Time Password>0.0.0, <1.3.0
One Time Password Project One Time Password Drupal>=8.x-1.0<8.x-1.3
Event History
May 21, 2025
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48012?
CVE-2025-48012 is classified as a high severity vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2025-48012?
To fix CVE-2025-48012, upgrade Drupal One Time Password to version 1.3.0 or later.
3
What systems are affected by CVE-2025-48012?
CVE-2025-48012 affects all versions of Drupal One Time Password prior to 1.3.0.
4
Can CVE-2025-48012 be exploited remotely?
Yes, CVE-2025-48012 can be exploited remotely by services with stolen credentials.
5
What type of vulnerability is CVE-2025-48012?
CVE-2025-48012 is an authentication bypass by capture-replay vulnerability.