{"id":"DRUPAL-CONTRIB-2019-062","details":"This module improves the Drupal login page with the new features and layout.\n\nThe module doesn't sufficiently filter input text in the administration pages text configuration inputs. For example, the login text field.\n\nThe vulnerability is mitigated by the fact it can only be exploited by a user with the \"Administer super login\" permission.","modified":"2026-09-10T03:46:13.068093108Z","published":"2019-08-14T17:14:00Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2019-062"}],"affected":[{"package":{"name":"drupal/super_login","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/super_login?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0"}],"database_specific":{"constraint":"\u003c1.3.0"}}],"database_specific":{"affected_versions":"\u003c1.3.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/super_login/DRUPAL-CONTRIB-2019-062.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mitch Portier","contact":["https://www.drupal.org/user/2284182"]}]}