PT-2024-10096 · Drupal · Login Disable
Benji Fisher
+3
·
Published
2024-12-11
·
Updated
2025-01-10
·
CVE-2024-13309
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Login Disable versions 2.0.0 through 2.1.0
Description
The issue is related to an Improper Authentication vulnerability in the Login Disable module for the Drupal CMS, which can be exploited due to incorrectly configured access control security levels. This allows a remote attacker to bypass existing security restrictions.
Recommendations
For versions 2.0.0 through 2.1.0, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Login Disable module to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Login Disable