PT-2026-56659 · Drupal · Login Disable
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Login Disable versions 0.0.0 through 2.1.4
Description
The Login Disable module, which restricts site access by requiring a secret key on the login form, does not sufficiently protect the form from brute force attacks. An attacker could potentially bypass this protection by guessing the secret key, depending on its length. This issue is partially mitigated because the attacker still requires a valid username and password to gain access.
Recommendations
Update Drupal Login Disable to a version newer than 2.1.4 to enable flood control that blocks excessive authentication attempts.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Login Disable