CVE-2024-13264: Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13264?
CVE-2024-13264 is a high severity vulnerability due to its potential for PHP Local File Inclusion in the Drupal Opigno module.
How do I fix CVE-2024-13264?
To fix CVE-2024-13264, upgrade the Opigno module to version 3.1.2 or later.
Which versions of the Opigno module are affected by CVE-2024-13264?
CVE-2024-13264 affects all versions of the Opigno module from 0.0.0 up to but not including 3.1.2.
What types of vulnerabilities does CVE-2024-13264 represent?
CVE-2024-13264 represents an Improper Neutralization of Directives in Statically Saved Code, commonly known as Static Code Injection.
What impact does CVE-2024-13264 have on Drupal installations?
The impact of CVE-2024-13264 can lead to unauthorized access and exploitation of local files on affected Drupal installations.