CVE-2020-36389: CSRF
Published Jun 17, 2021
·Updated
In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
Affected Software
2 affected components
CiviCRM CiviCRM<5.27.5
CiviCRM CiviCRM<5.28.1
Event History
Jun 17, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36389?
CVE-2020-36389 is classified as a medium severity vulnerability that allows CSRF in the CKEditor configuration form.
2
How do I fix CVE-2020-36389?
To fix CVE-2020-36389, upgrade to CiviCRM version 5.28.1 or later, or 5.27.5 ESR or later.
3
What impact does CVE-2020-36389 have on CiviCRM?
CVE-2020-36389 can lead to unauthorized actions being performed through CSRF attacks on the CKEditor configuration form.
4
Which versions of CiviCRM are affected by CVE-2020-36389?
CVE-2020-36389 affects CiviCRM versions before 5.28.1 and CiviCRM ESR versions before 5.27.5 ESR.
5
Is there a workaround for CVE-2020-36389?
There are no documented workarounds for CVE-2020-36389; updating to a patched version is recommended.