Junglewise Threat Intelligence
CVE-2024-13288: DRUPAL-CONTRIB-2024-052 - This module enables you to group nodes within pages that have a highly-granular, distributed permissions structure. In certain cases the mo
CVE-2024-13288 · Severity: info · Published 2024-10-23
Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Monster Menus. Vendors: Packagist:Https://Packages.Drupal.Org/8.
Executive brief
This module enables you to group nodes within pages that have a highly-granular, distributed permissions structure.
In certain cases the module doesn't sufficiently sanitize data before passing it to PHP's unserialize() function, which can result in arbitrary code execution.
Affected products
- packagist:https://packages.drupal.org/8 drupal/monster_menus