CVE-2014-3453: Flag Module Project Flag
Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.
Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area to admin/structure/flags/import. NOTE: this issue could also be exploited by other attackers if the administrator ignores a security warning on the permissions assignment page.
Affected products
- Flag Module Project Flag: up to and including 7.x-3.5; version 7.x-3.0 only; version 7.x-3.1 only; version 7.x-3.2 only; version 7.x-3.3 only; version 7.x-3.4 only; …
Published 2014-05-17. Last modified 2026-06-17.