CiviCRM versions 5.10.2 and earlier
CIviCRM versions 5.10.3 and 5.7.4
This vulnerability allowed attackers to access the content of arbitrary files (in a common configuration).
NOTE: The patch-set for this issue overlapped with the patch-set for CIVI-SA-2019-01, but the cause, exploit, and risks are distinct.
Upgrade to the latest CiviCRM 5.10.3+ or 5.7.4+.
Eileen McNuaghton of Wikimedia and Tim Otten of CiviCRM for identifying the issue.
Eileen McNuaghton of Wikimedia, Seamus Lee of Australian Greens, and Tim Otten of CiviCRM for fixing the issue.