CVE-2014-9151: Services Project Services

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

Affected products

Published 2014-12-01. Last modified 2026-06-17.