CVE-2024-13267: Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13267?
CVE-2024-13267 has a high severity rating due to its potential for PHP Local File Inclusion vulnerabilities.
How do I fix CVE-2024-13267?
To fix CVE-2024-13267, upgrade the Opigno TinCan Question Type plugin to version 7.X-1.3 or later.
What systems are affected by CVE-2024-13267?
CVE-2024-13267 affects the Opigno TinCan Question Type versions from 7.X-1.0 to before 7.X-1.3.
What type of vulnerability is CVE-2024-13267?
CVE-2024-13267 is categorized as a Static Code Injection vulnerability due to improper neutralization of directives.
What consequences could result from exploiting CVE-2024-13267?
Exploitation of CVE-2024-13267 could lead to unauthorized access to sensitive files on the server through PHP Local File Inclusion.