Executive brief
This module enables users to log in by email address with minimal configurations.
Drupal core contains protection against brute force attacks via a flood control mechanism. This module's functionality did not replicate the flood control, enabling brute force attacks.
A previous security advisory, [SA-CONTRIB-2023-45](https://www.drupal.org/sa-contrib-2023-045), was released for this issue, but that release did not successfully address the vulnerability. This security advisory and updated module version supersede the previous one.
Affected products
- packagist:https://packages.drupal.org/8 drupal/mail_login