PT-2024-10138 · Drupal · Megamenu Framework

Drew Webber

·

Published

2024-12-04

·

Updated

2025-01-14

·

CVE-2024-13299

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Megamenu Framework versions .
Description The issue is related to insufficient input validation in the Megamenu Framework module of the Drupal CMS, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations For Megamenu Framework versions .: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-00400
CVE-2024-13299

Affected Products

Megamenu Framework