CVE-2024-13265: Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13265?
CVE-2024-13265 has a medium severity rating due to its potential to allow PHP Local File Inclusion.
How do I fix CVE-2024-13265?
To fix CVE-2024-13265, update your Drupal Opigno Learning path to version 3.1.2 or later.
Which versions of Drupal Opigno Learning path are affected by CVE-2024-13265?
CVE-2024-13265 affects all versions of Drupal Opigno Learning path from 0.0.0 up to, but not including, 3.1.2.
What type of vulnerability is CVE-2024-13265?
CVE-2024-13265 is classified as an Improper Neutralization of Directives in Statically Saved Code, also known as Static Code Injection.
Can CVE-2024-13265 be exploited remotely?
Yes, CVE-2024-13265 can potentially be exploited remotely due to the nature of the PHP Local File Inclusion vulnerability.