Impact
The Drupal module Email Login OTP contains an input validation flaw (CWE‑20) that allows an attacker to supply forged or replayed one‑time passwords, effectively bypassing the authentication process. Based on the description, it is inferred that once the OTP is incorrectly verified, an attacker can log in as the target user and gain all privileges associated with that account. The flaw therefore threatens account confidentiality and integrity and could lead to full site takeover if an attacker can compromise privileged accounts.
Affected Systems
Drupal Email Login OTP, the module used within the Drupal CMS, is affected. No specific version range is listed because the advisory lists versions as "*.*", indicating that every released version of the module is potentially vulnerable. Administrators should examine any installation of this module regardless of its numeric version.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not in the CISA KEV catalog, implying no documented operational exploitation. Attackers would likely target the OTP verification endpoint, which is remotely accessible over the Internet, but the exact attack vector is not detailed in the advisory. The combination of a moderate score, low exploitation likelihood, and absence of KEV entries means the risk remains moderate and should be addressed before exploitation occurs.
OpenCVE Enrichment