Security Risk: 
Highly Critical
Access Bypass
Affected Versions: 

CiviCRM versions 5.10.2 and earlier


Fixed Versions: 

CIviCRM versions 5.10.3 and 5.7.4


Publication Date: 
Friday, February 22, 2019

This vulnerability allowed attackers to access the content of arbitrary files (in a common configuration).

NOTE: The patch-set for this issue overlapped with the patch-set for CIVI-SA-2019-01, but the cause, exploit, and risks are distinct.


Upgrade to the latest CiviCRM 5.10.3+ or 5.7.4+.



Eileen McNuaghton of Wikimedia and Tim Otten of CiviCRM for identifying the issue.

Eileen McNuaghton of Wikimedia, Seamus Lee of Australian Greens, and Tim Otten of CiviCRM for fixing the issue.