Drupal Opigno Module PHP Local File Inclusion Vulnerability

Vulnerability

A static code injection vulnerability allowing PHP local file inclusion has been identified in the Drupal Opigno module, affecting versions prior to 3.1.2. This issue arises from improper validation of uploaded files, which could lead to arbitrary file uploads and potentially allow remote code execution. The vulnerability requires the attacker to have a role with permission to create Opigno TinCan activities.

Impact

Exploitation of this vulnerability could lead to arbitrary PHP code execution on the server.

Remediation

Users of the Opigno module should upgrade to version 3.1.2 or later.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.