DRUPAL-CONTRIB-2024-029

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/opigno_learning_path/DRUPAL-CONTRIB-2024-029.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-029
Aliases
Published
2024-08-07T17:36:15Z
Modified
2026-09-10T03:45:53Z
Summary
[none]
Details

The Opigno Learning Path module enables you to manage group content.

Administrative forms allow uploading malicious files which may contain arbitrary code (RCE) or cross site scriptiong (XSS). These forms were not adequately controlled with permissions that communicate the severity of the permission.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Manage group content in any group".

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/opigno_learning_path

Package

Name
drupal/opigno_learning_path
Purl
pkg:composer/drupal/opigno_learning_path?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.2
Database specific
Show details
{
    "constraint": "<3.1.2"
}

Database specific

affected_versions
"<3.1.2"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/opigno_learning_path/DRUPAL-CONTRIB-2024-029.json"