File Upload Vulnerability in CiviCRM by CiviCRM
CVE-2020-36388
8.8HIGH
What is CVE-2020-36388?
In CiviCRM versions prior to 5.21.3 and between 5.22.x and 5.24.x before 5.24.3, a security flaw allows users to upload and execute a specially crafted PHAR archive, which could lead to remote code execution. This vulnerability poses a significant risk as it enables unauthorized users to manipulate the application and execute malicious code within the server environment.
