Description
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
Remediation
References
Related Vulnerabilities
MongoDb CVE-2017-15535 Vulnerability (CVE-2017-15535)
ProjectSend Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2018-7201)
WordPress Plugin Really Simple Guest Post Local File Inclusion (1.0.6)
Joomla Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-4104)
MySQL Deserialization of Untrusted Data Vulnerability (CVE-2019-14893)