Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088
  • Date: Wed, 9 Jul 2025 16:37:41 +0000 (UTC)
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=KJE5amjS; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; dmarc=pass (policy=none) header.from=drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 1FEC040811
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 245406073B
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2025-088

Project: Mail Login [1]
Date: 2025-July-09
Security risk: *Critical* 15 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: >3.0.0 <3.2.0 || >=4.0.0 <4.2.0
CVE IDs: CVE-2025-7393
Description: 
This module enables users to login by email address with the minimal
configurations.

The module included some protection against brute force attacks on the login
form, however they were incomplete. An attacker could bypass the brute force
protection allowing them to potentially gain access to an account.

Solution: 
Install the latest version:

* If you use the mail_login 3.x, upgrade to Mail Login 3.2.0 [3]
* If you use the mail_login 4.x, upgrade to Mail Login 4.2.0 [4]

Reported By: 
* Ryugo Kinoshita (dc-kinoshita) [5]

Fixed By: 
* Damien McKenna (damienmckenna) [6] of the Drupal Security Team
* Mohammad AlQanneh (mqanneh) [7]

Coordinated By: 
* Greg Knaddison (greggles) [8] of the Drupal Security Team


[1] https://www.drupal.org/project/mail_login
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/mail_login/releases/3.2.0
[4] https://www.drupal.org/project/mail_login/releases/4.2.0
[5] https://www.drupal.org/u/dc-kinoshita
[6] https://www.drupal.org/u/damienmckenna
[7] https://www.drupal.org/u/mqanneh
[8] https://www.drupal.org/u/greggles

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088, security-news, 09.07.2025

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang