Impact
The vulnerability is reported for the Drupal PanKM module, but the official description provides no detail about the weakness or attacker capabilities. The module is listed as Critical and Unsupported, indicating that this issue was never maintained beyond a certain date. Because the advisory lacks a specific attack path, the exact impact—such as remote code execution, privilege escalation, or data disclosure—cannot be determined from the information provided.
Affected Systems
Drupal installations that include the PanKM module are affected. All documented versions are considered impacted, but no further version granularity is provided.
Risk and Exploitability
No CVSS, EPSS, or KEV data are available. The EPSS score is not provided, and the KEV flag indicates that this vulnerability is not listed in the CISA KEV catalog. The vendor’s classification as Critical and Unsupported implies a severe potential impact, but no official patch or workaround is documented. Until a fix is released, the risk remains uncertain but could be significant for systems still running the PanKM module.
OpenCVE Enrichment