PT-2024-10353 · Opigno · Opigno

Andrii Aleksandrov

+6

·

Published

2024-08-07

·

Updated

2025-08-27

·

CVE-2024-13264

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Opigno module versions 0.0.0 through 3.1.2
Description The issue is related to improper neutralization of directives in statically saved code, also known as 'Static Code Injection', which can lead to PHP Local File Inclusion. This allows a remote attacker to execute arbitrary code.
Recommendations For Opigno module versions 0.0.0 through 3.1.2, update to version 3.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Opigno module until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-00854
CVE-2024-13264
DRUPAL-CONTRIB-2024-028

Affected Products

Opigno