Impact
An attacker can bypass authentication by using an alternate path or channel within Drupal Internationalization Single Sign-On. This flaw allows unauthorized users to obtain successful login tokens or access privileges that they should not possess. The weakness is a typical authentication bypass (CWE-288) which compromises the confidentiality and integrity of user sessions and potentially any data accessed thereafter.
Affected Systems
All Drupal Internationalization Single Sign-On installations from version 0.0.0 up to and including 1.8.0 are affected. The vulnerability exists in the module’s handling of alternate sign‑on paths.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an alternate authentication URL that an attacker can construct and use to obtain a valid session. The exploitation requires only access to the application’s domain and knowledge of the module’s URL structure. The severity is potentially high due to the complete bypass of authentication controls.
OpenCVE Enrichment