Skip to content
No results
Menu
Web Hosting and IT Consultancy ServicesWeb Hosting and IT Consultancy Services
  • About Us
  • Blog
  • Payment Option
  • Support
  • We are hiring
Sign Up
  • Home
  • Security
  • Release
Web Hosting and IT Consultancy ServicesWeb Hosting and IT Consultancy Services

Drupal Login Time Restriction Cross-Site Request Forgery Vulnerability (CVE-2025-13982) — High Severity

  • Alex JosephAlex Joseph
  • February 19, 2026
  • Security

In the intricate landscape of web security, certain vulnerabilities lurk with the potential to undermine user trust and system integrity. One such threat is Cross-Site Request Forgery (CSRF), often pronounced ‘sea-surf.’ This cunning attack method exploits the trust a web application has in a user’s browser. Essentially, a CSRF attack tricks your web browser into performing unwanted actions on a website where you are already logged in, without your knowledge. Recently, a significant CSRF vulnerability, identified as CVE-2025-13982, was discovered in the popular Login Time Restriction module for Drupal. This flaw presents a substantial risk, as it could allow attackers to manipulate your site by forcing authenticated users to execute unauthorized commands.

CVE Details

This particular vulnerability, identified as CVE-2025-13982, involves the Login Time Restriction module, a popular add-on for Drupal websites. It was first made public on January 28, 2026. The vulnerability has been thoroughly analyzed, confirming its presence and potential impact.

  • Product Affected: Drupal Login Time Restriction module
  • Published Date: January 28, 2026
  • Severity: HIGH
  • Status: Analyzed

Affected Products

The Cross-Site Request Forgery flaw specifically impacts earlier versions of the Login Time Restriction module for Drupal. If your Drupal site uses this module, it is crucial to check its version.

The vulnerability affects:

  • Login Time Restriction module versions from 0.0.0 up to, but not including, 1.0.3.

This means any version before 1.0.3 is potentially at risk and should be addressed immediately.

Current Status

The status of this vulnerability is ‘Analyzed.’ This designation indicates that security experts have thoroughly investigated the flaw, understood its mechanics, and confirmed its existence. While ‘Analyzed’ means the problem is well-understood, it also implies that the responsibility now falls squarely on site administrators to implement the necessary fixes to protect their systems from potential exploitation.

Severity Level

Rated as ‘HIGH’ severity, the CVE-2025-13982 vulnerability demands immediate and serious attention from all Drupal site administrators. A high severity rating for a CSRF flaw indicates that the vulnerability is relatively easy to exploit and could lead to significant negative consequences. Attackers could craft malicious web pages or links that, when visited by a logged-in user, could trigger unintended actions on the Drupal site. Imagine an attacker tricking a site administrator into changing critical settings, adding new administrative users, or even deleting essential content, all through a single click. The potential impact spans from unauthorized data manipulation and loss of user trust to a complete compromise of the website’s operational integrity. This makes promptly addressing this vulnerability paramount for maintaining a secure online presence.

Possible Solutions

Protecting your Drupal website from this critical CSRF vulnerability is a straightforward yet essential task: you must update the Login Time Restriction module. Based on the information available, the vulnerability is effectively patched in version 1.0.3 and any subsequent versions.

  • Update Your Module: The most critical step is to update your Login Time Restriction module to version 1.0.3 or newer. This update contains the necessary security fixes to prevent CSRF attacks from being successful.
  • Regular Updates: This incident serves as a crucial reminder of the importance of keeping all your Drupal modules, themes, and the core system itself up to date. Regular updates are your primary and most effective line of defense against known security vulnerabilities.
  • Security Best Practices: Always educate your users and administrators to exercise caution with suspicious links or unsolicited emails. While technical updates are vital, user awareness adds an invaluable layer of protection.

While specific detailed upgrade instructions would typically be found on the official Drupal security advisory page (which, unfortunately, was inaccessible at the time of writing), the general and most effective solution is to upgrade to the patched version. For more general advice on maintaining your Drupal site’s security, you might find our article on ‘Essential Drupal Security Best Practices’ helpful.

References

For further details regarding this vulnerability, please refer to the following security advisory:

  • https://www.drupal.org/sa-contrib-2025-120
Tags
# CSRF# Drupal# Login Time Restriction# Vulnerability# Web Security
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.

Previous Post Drupal AI Cross-Site Scripting Vulnerability (CVE-2025-13981) — Medium Severity
Next Post RapidLoad Power-Up for Autoptimize Unauthorized Cache Modification Vulnerability (CVE-2023-1334) — Medium Severity

Recent Posts

  • n8n Credential Authorization Bypass Vulnerability (CVE-2026-72774) — Medium Severity
  • n8n Account Takeover Vulnerability (CVE-2026-72772) — High Severity
  • n8n Prototype Pollution Vulnerability (CVE-2026-72769) — High Severity
  • n8n Remote Code Execution Vulnerability (CVE-2026-72767) — High Severity
  • n8n Module Cache Poisoning Vulnerability (CVE-2026-72764) — HIGH Severity

Related Posts

n8n Credential Authorization Bypass Vulnerability (CVE-2026-72774) — Medium Severity

  • Alex Joseph
  • September 19, 2026

n8n Account Takeover Vulnerability (CVE-2026-72772) — High Severity

  • Alex Joseph
  • September 18, 2026

n8n Prototype Pollution Vulnerability (CVE-2026-72769) — High Severity

  • Alex Joseph
  • September 18, 2026

Servers

  • Self Managed Dedicated Server
  • Managed Dedicated Server
  • Low Cost Dedicated Server
  • Gaming Dedicated Server
  • Dedicated server for Siberian CMS
  • Shoutcast Dedicated Server
  • Flussonic Dedicated Server

Servers Locations

  • Dedicated Servers in India
  • Dedicated Servers in China
  • Dedicated Servers in Russia
  • Dedicated Servers in Canada
  • Dedicated Servers in UK
  • Dedicated Servers in Turkey
  • Dedicated Servers in Japan

Hosting

  • Web Hosting
  • Premium cPanel Hosting
  • Reseller Hosting
  • Shared Hosting
  • Shoutcast Hosting
  • Online Radio Hosting

Solutions

  • Software Installations
  • Hire an Expert
  • Server Monitoring
  • Server Administrators
  • Hosting Support
  • cPanel Management

The Ucartz Online Pvt. Ltd. incorporated under the Ministry of Corporate Affairs, India [CIN: U72200KL2017PTC048470] and the GST Identification Number: 32AACCU0519P1ZA. By using this site, you signify that you agree to be bound by Ucartz TOS.