CVE-2013-4178
Google Authenticator Login Module < 6.x-1.2 / 7.x-1.4 - Authentication Bypass via OTP Replay
Title source: llmDescription
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
https://drupal.org/node/1995634
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/59884
Various Sources x_refsource_misc
https://drupal.org/node/1995706
Various Sources x_refsource_confirm
https://drupal.org/node/1995482
Scores
EPSS
0.0130
EPSS Percentile
66.8%
Details
CWE
CWE-287
Status
published
Products (7)
google_authenticator_login_project/ga_login
6.x-1.0 alpha1 (3 CPE variants)
google_authenticator_login_project/ga_login
6.x-1.1
google_authenticator_login_project/ga_login
6.x-1.x dev
google_authenticator_login_project/ga_login
7.x-1.0 (3 CPE variants)
google_authenticator_login_project/ga_login
7.x-1.1
google_authenticator_login_project/ga_login
7.x-1.2
google_authenticator_login_project/ga_login
7.x-1.3
Published
May 29, 2014
Tracked Since
Feb 18, 2026