Impact
The Drupal Flag attendance field module contains an improper handling of dynamically determined PHP object attributes. An attacker can supply specially crafted input that causes the module to modify object attributes without proper validation, resulting in PHP object injection. The flaw is described as CWE‑915, allowing an attacker to inject arbitrary objects that may alter application behavior or compromise data integrity.
Affected Systems
All installations of the Drupal Flag attendance field module with a version from 0.0.0 through 1.2 are vulnerable, irrespective of other Drupal components.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% suggests a low probability of public exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker submitting crafted input through the flag attendance web form, leading to PHP object injection. At the time of writing, there is no public patch available; administrators should monitor the Drupal security advisory for an update.
OpenCVE Enrichment