CVE Vulnerabilities

CVE-2025-48011

Authentication Bypass Using an Alternate Path or Channel

Published: May 21, 2025 | Modified: Jun 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
One_time_password One_time_password_project 8.x-1.0 (including) 8.x-1.3 (excluding)

Potential Mitigations

References