CVE-2013-0258
Google Authenticator Login GA Login - Authentication Bypass
Title source: ruleDescription
The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.
Scores
EPSS
0.0027
EPSS Percentile
49.8%
Classification
CWE
CWE-287
Status
draft
Affected Products (5)
google_authenticator_login_project/ga_login
google_authenticator_login_project/ga_login
google_authenticator_login_project/ga_login
google_authenticator_login_project/ga_login
google_authenticator_login_project/ga_login
Timeline
Published
Mar 27, 2013
Tracked Since
Feb 18, 2026