{"id":"DRUPAL-CONTRIB-2024-073","details":"This module enables you to prevent existing users from logging in to your Drupal site unless they know the secret key to add to the end of the ?q=user login form page.\n\nThe Login Disable module does not correctly prevent a user with a disabled login from logging in, allowing those users to by-pass the protection offered by the module.\n\nThis vulnerability is mitigated by the fact that an attacker must already have a user account to log in. This bug therefore allows users to log in even if their login is disabled.","aliases":["CVE-2024-13309"],"modified":"2026-09-10T03:46:02.949917911Z","published":"2024-12-11T12:36:29Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-073"}],"affected":[{"package":{"name":"drupal/login_disable","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/login_disable?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.1.1"}],"database_specific":{"constraint":"\u003e=2.0.0 \u003c2.1.1"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/login_disable/DRUPAL-CONTRIB-2024-073.json","affected_versions":"\u003e=2.0.0 \u003c2.1.1"}}],"schema_version":"1.9.0","credits":[{"name":"e5sego","contact":["https://www.drupal.org/user/261590"]}]}