Drupal Protected Pages
cpe:2.3:a:protected_pages_project:protected_pages:*:*:*:*:drupal:*:*
- < 1.8.0
A vulnerability allowing brute force attacks has been identified in the Drupal Protected Pages module, affecting versions prior to 1.8.0. The issue arises because the module does not limit the number of password attempts, allowing attackers to repeatedly guess passwords. This vulnerability is somewhat mitigated by the requirement to know the specific URL of the protected page.
Exploitation of this vulnerability could lead to unauthorized access bypass, allowing attackers to access protected pages without proper authentication.
Users of the Protected Pages module for Drupal 8.x should upgrade to Protected Pages 8.x-1.8.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.