CVE-2020-36388: Malicious File Upload
Published Jun 17, 2021
·Updated
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Affected Software
2 affected components
CiviCRM CiviCRM<5.21.3
CiviCRM CiviCRM>=5.22.0<5.24.3
Event History
Jun 17, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36388?
The severity of CVE-2020-36388 is classified as high due to the potential for remote code execution.
2
How do I fix CVE-2020-36388?
To fix CVE-2020-36388, upgrade CiviCRM to version 5.21.3 or later, or to version 5.24.3 or later.
3
Who is affected by CVE-2020-36388?
CVE-2020-36388 affects CiviCRM versions prior to 5.21.3 and any 5.22.x to 5.24.x versions before 5.24.3.
4
What types of attacks can exploit CVE-2020-36388?
CVE-2020-36388 can be exploited to upload and execute malicious PHAR archive files.
5
Where can I find more information about CVE-2020-36388?
For more information about CVE-2020-36388, refer to CiviCRM security advisories or trusted cybersecurity blogs.