Junglewise Threat Intelligence

CVE-2025-48012: DRUPAL-CONTRIB-2025-063 - This module enables you to allow users to include a second authentication method in addition to password authentication. The module doesn't

CVE-2025-48012 · Severity: info · Published 2025-05-14

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/One Time Password. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables you to allow users to include a second authentication method in addition to password authentication.

The module doesn't sufficiently prevent the same TFA token within a 30 second window.

This vulnerability is mitigated by the fact that an attacker must obtain a valid username/password and second factor.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/one_time_password

Related threats