Impact
The vulnerability enables an attacker to bypass authentication by exploiting an alternate path or channel provided by the Drupal Disable Login Page module. This allows the execution of functions without proper credentials, resulting in unauthorized access to site administration and sensitive content. The weakness is classified as Improper Authentication (CWE‑288).
Affected Systems
Drupal sites that have the Disable Login Page module installed between versions 0.0.0 and 1.1.4 are susceptible. This includes any deployment of the module in Drupal environments that rely on the default authentication flow.
Risk and Exploitability
The exploit requires the attacker to know or guess the alternate URL or to identify the module’s routing mechanism. Because the EPSS score is < 1%, the likelihood of exploitation is low, but the vulnerability’s CVSS score of 4.1 indicates moderate severity. Because the KEV catalog lists it as not listed, there is no known exploitation yet, so it should be treated with caution. An attacker who successfully bypasses authentication can compromise confidentiality, integrity, and availability of the affected site.
OpenCVE Enrichment