CIVI-SA-2019-08: Arbitrary File Read

2019-02-22 09:00
Written by

This vulnerability allowed attackers to access the content of arbitrary files (in a common configuration).

NOTE: The patch-set for this issue overlapped with the patch-set for CIVI-SA-2019-01, but the cause, exploit, and risks are distinct.

Security Risk
Highly Critical
Access Bypass
Affected Versions

CiviCRM versions 5.10.2 and earlier


Fixed Versions

CIviCRM versions 5.10.3 and 5.7.4



Upgrade to the latest CiviCRM 5.10.3+ or 5.7.4+.



Eileen McNuaghton of Wikimedia and Tim Otten of CiviCRM for identifying the issue.

Eileen McNuaghton of Wikimedia, Seamus Lee of Australian Greens, and Tim Otten of CiviCRM for fixing the issue.