CRITICAL🇵🇱 Wersja polska

CVE-2025-7393

CVSS 9.8v3.1pub. 2025-07-21upd. 2025-08-27

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-307 consists of the lack of proper mechanism for blocking or limiting successive login attempts after a specified number of failed authentications. An attacker can freely send an unlimited number of login requests over the network (vector AV:N), without needing any privileges and without user interaction. This allows automated and mass testing of password combinations to take over a user account.

Impact

A successful brute force attack can lead to account takeover, including administrative accounts, resulting in complete loss of confidentiality, integrity, and availability of the application.

Mitigation & patch

The Mail Login module should be updated to version 3.2.0 or higher (for the 3.x branch) or to version 4.2.0 or higher (for the 4.x branch). Details are available in the Drupal security advisory: https://www.drupal.org/sa-contrib-2025-088

Who is affected

Mqanneh Mail Login module for Drupal in versions from 3.0.0 to 3.2.0 (exclusive) and from 4.0.0 to 4.2.0 (exclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mqanneh Mail Login

    APP
    Mqanneh
    3.0.0 – 3.2.0 (excl.)4.0.0 – 4.2.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References