Drupal Mail Login Brute Force Vulnerability

Vulnerability

A brute force vulnerability has been identified in the Drupal Mail Login module, specifically in versions 3.0.0 prior to 3.2.0 and 4.0.0 prior to 4.2.0. The issue arises from improper restriction of excessive authentication attempts, allowing attackers to bypass existing brute force protections and potentially gain unauthorized access to user accounts.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user accounts by bypassing the module's brute force protection mechanisms.

Remediation

Users of Mail Login 3.x should upgrade to version 3.2.0, and users of Mail Login 4.x should upgrade to version 4.2.0.

Added: Jul 21, 2025, 5:27 PM
Updated: Jul 21, 2025, 5:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.