The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist of callbacks."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.0%