Junglewise Threat Intelligence

CVE-2024-13265: DRUPAL-CONTRIB-2024-029 - The Opigno Learning Path module enables you to manage group content. Administrative forms allow uploading malicious files which may contain

CVE-2024-13265 · Severity: info · Published 2024-08-07

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Opigno Learning Path. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Opigno Learning Path module enables you to manage group content.

Administrative forms allow uploading malicious files which may contain arbitrary code (RCE) or cross site scriptiong (XSS). These forms were not adequately controlled with permissions that communicate the severity of the permission.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Manage group content in any group".

Affected products

  • packagist:https://packages.drupal.org/8 drupal/opigno_learning_path

Related threats