CVE-2024-13263: Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue affects Opigno group manager: from 0.0.0 before 3.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13263?
CVE-2024-13263 is classified as a high-severity vulnerability due to its potential for PHP Local File Inclusion.
How do I fix CVE-2024-13263?
To fix CVE-2024-13263, update the Drupal Opigno group manager to version 3.1.1 or later.
What versions of Opigno group manager are affected by CVE-2024-13263?
CVE-2024-13263 affects all versions of Opigno group manager from 0.0.0 up to but not including 3.1.1.
What kind of vulnerability is CVE-2024-13263?
CVE-2024-13263 is a Static Code Injection vulnerability that allows improper neutralization of directives.
Can CVE-2024-13263 lead to remote code execution?
While CVE-2024-13263 facilitates Local File Inclusion, it may potentially lead to remote code execution if exploited.