Impact
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal Plotly.js Graphing creates a PHP object injection flaw. The flaw allows a malicious actor to manipulate object attributes that are dynamically chosen, potentially injecting crafted objects that can alter program flow or execute arbitrary code. This weakness, classified as CWE‑915, can compromise the integrity and confidentiality of the affected Drupal installation by enabling remote code execution or unauthorized actions within the application context.
Affected Systems
Drupal users who have the Plotly.js Graphing module installed are impacted. The flaw affects module versions ranging from 0.0.0 up through 3.0.2. Administrators should verify the module version and upgrade if installed in this range.
Risk and Exploitability
The likely attack vector is through user input fields processed by the module. Based on the description, it is inferred that the attacker would need to send crafted data that directs the module to instantiate objects with malicious attributes. The CVSS score of 8.1 indicates a high severity, and the EPSS score of <1% suggests a low but non‑zero probability of exploitation at this time. The vulnerability is not in the CISA KEV catalog, implying no known widespread exploitation yet. If exploited, object injection could lead to remote code execution or unauthorized actions within the Drupal application.
OpenCVE Enrichment