CVE-2020-36388

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
17/06/2021
Last modified:
03/02/2023

Description

In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:civicrm:civicrm:*:*:*:*:*:*:*:* 5.21.3 (excluding)
cpe:2.3:a:civicrm:civicrm:*:*:*:*:*:*:*:* 5.22.0 (including) 5.24.3 (excluding)