Impact
The vulnerability found in Drupal Email Login OTP potentially allows an attacker to bypass the one‑time password authentication, granting unauthorized access to user accounts. This flaw arises from the module’s improper handling of the OTP verification process, which may enable credential replay or acceptance of forged OTPs, thereby compromising account confidentiality and integrity. The explicit technical details of the flaw are not fully disclosed in the public advisory, but the impact described strongly suggests that compromised credentials could lead to elevated privileges or full site takeover if exploited.
Affected Systems
Drupal Email Login OTP is the affected product under the Drupal environment. No specific version range is listed; the advisory indicates that all versions represented by "*.*" are vulnerable. Administrators should treat any installation of the Email Login OTP module as potentially impacted.
Risk and Exploitability
The CVSS score is not publicly available, and EPSS is listed as not available, leaving a formal risk quantification absent. The vulnerability is not yet included in the CISA KEV catalog, which suggests there are no confirmed exploitation reports. The attack vector cannot be definitively determined from the published data; it is likely remote but remains speculative. Based on the severity implied by the potential for authentication bypass, the risk remains unquantified but appears significant enough to merit urgency, pending vendor remediation. Attackers would need to exploit the flawed OTP logic, possibly through guess or replay, to gain unauthorized access.
OpenCVE Enrichment