{"id":"CVE-2025-7393","summary":"Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088","details":"Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.","aliases":["DRUPAL-CONTRIB-2025-088"],"modified":"2026-08-12T03:51:30.113078714Z","published":"2025-07-21T16:35:45.527Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7393.json","cna_assigner":"drupal","cwe_ids":["CWE-307"]},"references":[{"type":"WEB","url":"https://git.drupalcode.org/project/mail_login"},{"type":"WEB","url":"https://www.drupal.org/project/mail_login"},{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-088"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7393.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7393"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.drupalcode.org/project/mail_login","events":[{"introduced":"01d8bd9b7d4db9b794ac9dda9ebe0ae5970725b1"},{"fixed":"19d734c3c5ea28fac9c137ea7c1fc8771d083a32"},{"introduced":"9d7faed4ee28db61eee05506bdf08de360be2933"},{"fixed":"abd79da75861f97bf57d862e53072dabc479b9eb"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.2.0"},{"introduced":"4.0.0"},{"fixed":"4.2.0"}],"source":"AFFECTED_FIELD"}}],"versions":["3.1.0","3.0.1","4.0.3","4.0.2","4.0.1","4.0.0-alpha1","4.0.0","3.0.0","3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7393.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}