Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.
The vulnerability classified as CWE-307 consists of the lack of proper mechanism for blocking or limiting successive login attempts after a specified number of failed authentications. An attacker can freely send an unlimited number of login requests over the network (vector AV:N), without needing any privileges and without user interaction. This allows automated and mass testing of password combinations to take over a user account.
A successful brute force attack can lead to account takeover, including administrative accounts, resulting in complete loss of confidentiality, integrity, and availability of the application.
The Mail Login module should be updated to version 3.2.0 or higher (for the 3.x branch) or to version 4.2.0 or higher (for the 4.x branch). Details are available in the Drupal security advisory: https://www.drupal.org/sa-contrib-2025-088
Mqanneh Mail Login module for Drupal in versions from 3.0.0 to 3.2.0 (exclusive) and from 4.0.0 to 4.2.0 (exclusive).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMqanneh Mail Login
APPMqanneh3.0.0 – 3.2.0 (excl.)4.0.0 – 4.2.0 (excl.)