File Upload Vulnerability in CiviCRM by CiviCRM
CVE-2020-36388

8.8HIGH

Key Information:

Vendor

Civicrm

Status
Vendor
CVE Published:
17 June 2021

What is CVE-2020-36388?

In CiviCRM versions prior to 5.21.3 and between 5.22.x and 5.24.x before 5.24.3, a security flaw allows users to upload and execute a specially crafted PHAR archive, which could lead to remote code execution. This vulnerability poses a significant risk as it enables unauthorized users to manipulate the application and execute malicious code within the server environment.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.