Description
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
3.0.0 (semver) before 3.2.0
4.0.0 (semver) before 4.2.0
Credits
Ryugo Kinoshita (dc-kinoshita)
Damien McKenna (damienmckenna)
Mohammad AlQanneh (mqanneh)
Greg Knaddison (greggles)
References
www.drupal.org/sa-contrib-2025-088