Static Code Injection Vulnerability in Drupal Opigno TinCan Question Type
CVE-2024-13267

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
9 January 2025

Summary

The Opigno TinCan Question Type for Drupal contains a Static Code Injection vulnerability that allows attackers to exploit improperly neutralized directives. This vulnerability enables PHP Local File Inclusion, which could lead to unauthorized access to sensitive files within the server. It specifically affects versions prior to 7.X-1.3, making it essential for users to upgrade to the latest version to mitigate potential security risks.

References

Timeline

  • Vulnerability published

.