Project: 
Date: 
2023-September-13
Vulnerability: 
Access bypass
Affected versions: 
<2.8.0
Description: 

This module enables users to log in by email address with minimal configurations.

Drupal core contains protection against brute force attacks via a flood control mechanism. This module's functionality did not replicate the flood control, enabling brute force attacks.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: