Lucene search

K
osvGoogleOSV:CVE-2020-36388
HistoryJun 17, 2021 - 7:15 p.m.

CVE-2020-36388

2021-06-1719:15:07
Google
osv.dev
4
civicrm
phar archive
upload
execution
security vulnerability

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

42.0%

In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

42.0%