Email Verification / SMS Verification / OTP Verification
2 security fixes in one update. Email Verification / SMS Verification / OTP Verification fixed 2 separate security bugs this week: 1 cross site scripting, 1 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-125, is explained here and the full list is at the end of the card.
The module does not properly filter user supplied text before displaying it. A visitor could read hidden data or change data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Email Verification / SMS Verification / OTP Verification to 8.x-2.4.
For developers: what the fix changed
The fix removes the insecure passing of error messages via the `q` URL parameter and its subsequent unescaped output in `otp_verification_form_user_register_form_alter` within `otp_verification.module`. It also updates message rendering in `src/Form/MiniorangeValidateUser.php` to use proper placeholders like `@msg` in the `t()` function and escapes the `tx_id` parameter to prevent XSS.
Also in this release The release also includes bug fixes related to session handling, cookie management, and redirect logic.
otp_verification.module+66 −47 fixsrc/Form/MiniorangeValidateUser.php+107 −56 fixsrc/MiniorangeOtpUtilities.php+19 −4src/Plugin/OtpValidation/OtpValidator.php+18 −2
- Critical · Cross Site Scripting · SA-CONTRIB-2026-125
- Critical · Access Bypass · SA-CONTRIB-2026-124