Drupal Login Disable
cpe:2.3:a:login_disable_project:login_disable:*:*:*:*:drupal:*:*
- < 2.1.3
An authentication bypass vulnerability has been identified in the Drupal Login Disable module, affecting versions prior to 2.1.3. This vulnerability allows users to log in without the required access key by exploiting the HTTP request login route, bypassing the module's intended functionality.
Exploitation of this vulnerability allows unauthorized users to bypass authentication requirements, potentially leading to unauthorized access to the Drupal site.
Users of the Login Disable module should upgrade to version 2.1.3.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.