PT-2026-5201 · Drupal · Drupal Login Time Restriction
Greg Knaddison
+4
·
Published
2026-01-28
·
Updated
2026-02-19
·
CVE-2025-13982
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Login Time Restriction versions prior to 1.0.3
Description
A Cross-Site Request Forgery (CSRF) issue exists in the Login Time Restriction module. This allows attackers to perform actions on behalf of authenticated users without their knowledge. The issue allows Cross Site Request Forgery.
Recommendations
Update the Login Time Restriction module to version 1.0.3 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal Login Time Restriction