PT-2026-5201 · Drupal · Drupal Login Time Restriction
Greg Knaddison
+4
·
Publicado
2026-01-28
·
Atualizado
2026-02-19
·
CVE-2025-13982
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Login Time Restriction versions prior to 1.0.3
Description
A Cross-Site Request Forgery (CSRF) issue exists in the Login Time Restriction module. This allows attackers to perform actions on behalf of authenticated users without their knowledge. The issue allows Cross Site Request Forgery.
Recommendations
Update the Login Time Restriction module to version 1.0.3 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal Login Time Restriction