Impact
The Disable Login Page module for Drupal fails to enforce limits on repeated authentication attempts, allowing attackers to perform brute‑force attacks and bypass normal login restrictions. This flaw can lead to unauthorized access to protected areas of the site. It represents a weakness in input validation and resource management.
Affected Systems
Drupal installations that have the Disable Login Page module installed and are running any released version from 0.0.0 through 1.1.4 fall under the affected population. The vulnerability spans all module releases in that range, so sites that have not upgraded beyond 1.1.4 remain exposed.
Risk and Exploitability
The CVSS score is 5.7, reflecting moderate severity, while the EPSS score is below 1%, indicating a low likelihood of current exploitation. It is not recorded in the CISA KEV catalog. Exploitation would occur over the network through the module’s login interface, requiring only repeated credential attempts. The combination of moderate severity and low exploitation probability means that remediation remains prudent to prevent potential unauthorized access.
OpenCVE Enrichment