First published: Thu Jun 17 2021(Updated: )
In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CiviCRM | <5.27.5 | |
CiviCRM | <5.28.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36389 is classified as a medium severity vulnerability that allows CSRF in the CKEditor configuration form.
To fix CVE-2020-36389, upgrade to CiviCRM version 5.28.1 or later, or 5.27.5 ESR or later.
CVE-2020-36389 can lead to unauthorized actions being performed through CSRF attacks on the CKEditor configuration form.
CVE-2020-36389 affects CiviCRM versions before 5.28.1 and CiviCRM ESR versions before 5.27.5 ESR.
There are no documented workarounds for CVE-2020-36389; updating to a patched version is recommended.