CVE-2013-4178: Medium severity Google Authenticator Login Project Ga Login vulnerability
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4178?
CVE-2013-4178 has a moderate severity level due to its potential to allow unauthorized access through replay attacks.
How do I fix CVE-2013-4178?
To fix CVE-2013-4178, upgrade the Google Authenticator login module to version 6.x-1.2 or 7.x-1.4 or later.
Which versions of the Google Authenticator login module are affected by CVE-2013-4178?
CVE-2013-4178 affects versions 6.x-1.0-alpha1, 6.x-1.0-beta1, 6.x-1.0-beta2, 6.x-1.1, and 7.x-1.0 through 7.x-1.3.
Can CVE-2013-4178 lead to data breaches?
Yes, CVE-2013-4178 can lead to data breaches by allowing attackers to authenticate as legitimate users.
Is CVE-2013-4178 a remote exploit vulnerability?
Yes, CVE-2013-4178 is considered a remote exploit vulnerability since it can be exploited remotely by attackers.