Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-27mc-9399-r9mx | Drupal Access code allows Brute Force Attempts |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-108 |
|
Fri, 12 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Access Code Project
Access Code Project access Code |
|
| CPEs | cpe:2.3:a:access_code_project:access_code:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Access Code Project
Access Code Project access Code |
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal access Code Drupal drupal |
|
| Vendors & Products |
Drupal
Drupal access Code Drupal drupal |
Thu, 30 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5. | |
| Title | Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108 | |
| Weaknesses | CWE-307 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-10-30T13:07:25.555Z
Reserved: 2025-09-24T16:53:11.887Z
Link: CVE-2025-10928
Updated: 2025-10-30T13:07:05.974Z
Status : Analyzed
Published: 2025-10-30T00:15:34.060
Modified: 2025-12-12T17:54:27.093
Link: CVE-2025-10928
No data.
OpenCVE Enrichment
Updated: 2025-10-30T14:37:43Z
Github GHSA