CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-13267: Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031

Description

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.

Classification

CVE ID: CVE-2024-13267

Affected Products

Vendor: Drupal

Product: Opigno TinCan Question Type

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-07 (when was this score calculated)

References

https://www.drupal.org/sa-contrib-2024-031

Timeline