Description
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4054 | The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method. |
Github GHSA |
GHSA-h3r9-pjmr-f938 | Drupal Brute force amplification attacks via XML-RPC |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T23:47:58.167Z
Reserved: 2016-03-15T00:00:00.000Z
Link: CVE-2016-3163
No data.
Status : Modified
Published: 2016-04-12T15:59:01.150
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-3163
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA