CVE-2024-13267

Source
https://cve.org/CVERecord?id=CVE-2024-13267
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-13267.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-13267
Published
2025-01-09T19:17:31.582Z
Modified
2026-08-12T03:51:40.489846968Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
Details

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.

Database specific
{
    "cna_assigner": "drupal",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/13xxx/CVE-2024-13267.json",
    "cwe_ids": [
        "CWE-96"
    ]
}
References

Affected packages

Git / git.drupalcode.org/project/opigno_tincan_question_type

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/opigno_tincan_question_type
Events
Introduced
9b52f4806705482d817be9cfe2536df48e3a2e04
Fixed
14c133f3f2bd0b4377da67908ce4a4b789dcadc7
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.x-1.0"
        },
        {
            "fixed": "7.x-1.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

7.*
7.x-1.0
7.x-1.1
7.x-1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-13267.json"