Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.0.0 (semver) before 1.3.0
Credits
Conrad Lara (cmlara)
danielveza
Kim Pepper (kim.pepper)
Lee Rowlands (larowlan)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-061
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.