Project: 
Project machine name: 
mail_login
Date: 
2023-October-04
Vulnerability: 
Access bypass
Affected versions: 
<2.9.0
Description: 

This module enables users to log in by email address with minimal configurations.

Drupal core contains protection against brute force attacks via a flood control mechanism. This module's functionality did not replicate the flood control, enabling brute force attacks.

A previous security advisory, SA-CONTRIB-2023-45, was released for this issue, but that release did not successfully address the vulnerability. This security advisory and updated module version supersede the previous one.

Solution: 

Install the latest version:

Fixed By: 
Coordinated By: