First published: Thu Jun 17 2021(Updated: )
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CiviCRM | <5.21.3 | |
CiviCRM | >=5.22.0<5.24.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-36388 is classified as high due to the potential for remote code execution.
To fix CVE-2020-36388, upgrade CiviCRM to version 5.21.3 or later, or to version 5.24.3 or later.
CVE-2020-36388 affects CiviCRM versions prior to 5.21.3 and any 5.22.x to 5.24.x versions before 5.24.3.
CVE-2020-36388 can be exploited to upload and execute malicious PHAR archive files.
For more information about CVE-2020-36388, refer to CiviCRM security advisories or trusted cybersecurity blogs.