Junglewise Threat Intelligence

CVE-2024-13309: DRUPAL-CONTRIB-2024-073 - This module enables you to prevent existing users from logging in to your Drupal site unless they know the secret key to add to the end of t

CVE-2024-13309 · Severity: info · Published 2024-12-11

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Login Disable. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables you to prevent existing users from logging in to your Drupal site unless they know the secret key to add to the end of the ?q=user login form page.

The Login Disable module does not correctly prevent a user with a disabled login from logging in, allowing those users to by-pass the protection offered by the module.

This vulnerability is mitigated by the fact that an attacker must already have a user account to log in. This bug therefore allows users to log in even if their login is disabled.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/login_disable

Related threats