Junglewise Threat Intelligence

CVE-2025-7393: DRUPAL-CONTRIB-2025-088 - This module enables users to login by email address with the minimal configurations. The module included some protection against brute forc

CVE-2025-7393 · Severity: info · Published 2025-07-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Mail Login. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables users to login by email address with the minimal configurations.

The module included some protection against brute force attacks on the login form, however they were incomplete. An attacker could bypass the brute force protection allowing them to potentially gain access to an account.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/mail_login

Related threats