Project: 
Project machine name: 
super_login
Date: 
2022-January-05
Vulnerability: 
Access bypass
Affected versions: 
<1.7.0
Description: 

This module enables you to login with an email address.

The module doesn't sufficiently check if a user account is active when using email login.

This vulnerability is mitigated by the fact that an attacker must have an account in the website that is blocked.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: