{"id":"DRUPAL-CONTRIB-2025-101","details":"This module enables you to protect individual pages with a password.\n\nThe module doesn't limit the number of password attempts, making it vulnerable to brute force attacks.\n\nThis vulnerability is mitigated by the fact that an attacker must know the protected page's URL.\n\n**CVSS risk score ([experimental](https://www.drupal.org/project/securitydrupalorg/issues/3442181)) 6.3 / Medium**\n\n[CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)","aliases":["CVE-2025-9551"],"modified":"2026-09-10T03:45:15.679067841Z","published":"2025-08-27T17:19:59Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-101"}],"affected":[{"package":{"name":"drupal/protected_pages","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/protected_pages?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0"}],"database_specific":{"constraint":"\u003c1.8.0"}}],"database_specific":{"affected_versions":"\u003c1.8.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/protected_pages/DRUPAL-CONTRIB-2025-101.json"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}