The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:20:41

Updated: 2022-10-03T16:20:41

Reserved: 2022-10-03T00:00:00


Link: CVE-2014-9152

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-12-01T16:59:02.463

Modified: 2014-12-01T19:04:46.007


Link: CVE-2014-9152

JSON object: View

cve-icon Redhat Information

No data.

CWE