Drupal Mail Login Brute Force Vulnerability
Vulnerability
A brute force vulnerability has been identified in the Drupal Mail Login module, specifically in versions 3.0.0 prior to 3.2.0 and 4.0.0 prior to 4.2.0. The issue arises from improper restriction of excessive authentication attempts, allowing attackers to bypass existing brute force protections and potentially gain unauthorized access to user accounts.
Impact
Exploitation of this vulnerability could lead to unauthorized access to user accounts by bypassing the module's brute force protection mechanisms.
Remediation
Users of Mail Login 3.x should upgrade to version 3.2.0, and users of Mail Login 4.x should upgrade to version 4.2.0.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
