Drupal Brute force amplification attacks via XML-RPC
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated May 3, 2024
Description
Published by the National Vulnerability Database
Apr 12, 2016
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 23, 2024
Last updated
May 3, 2024
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
References