CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hybridauth Social Login Project 1Hybridauth Social Login May 6, 2026 Aug 18, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login. |
1Hybridauth Social Login Project 1Hybridauth Social Login May 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with cert...Show more |