CVE-2024-13296: Mailjet - Moderately critical - Arbitrary PHP code execution - SA-CONTRIB-2024-062
Published Jan 9, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.
Affected Software
2 affected components
Mailjet Mailjet<4.0.1
Mailjet Mailjet Drupal<4.0.1
Event History
Jan 9, 2025
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13296?
CVE-2024-13296 is classified as a high severity vulnerability due to its potential for object injection.
2
How do I fix CVE-2024-13296?
To fix CVE-2024-13296, upgrade the Mailjet module to version 4.0.1 or later.
3
What causes CVE-2024-13296?
CVE-2024-13296 is caused by the deserialization of untrusted data leading to object injection vulnerabilities.
4
Which versions of Mailjet are affected by CVE-2024-13296?
CVE-2024-13296 affects all Mailjet versions prior to 4.0.1.
5
Is CVE-2024-13296 related to Drupal core?
CVE-2024-13296 is not a Drupal core vulnerability but affects the Mailjet module within Drupal.