The helper function CRM_Utils_File::cleanDir()
is used to cleanup certain data folders. In some situations, it might be tricked into deleting additional files outside of the target directory.
CiviCRM versions 5.78.1 and earlier
CiviCRM versions 5.78.2 and 5.75.4 (ESR)
Upgrade to the latest CiviCRM Version
- Reporter: Sebastian Lisken of civiservice.de
- Development/Review: Sebastian Lisken of civiservice.de; Tim Otten of CiviCRM; Dave D; Seamus Lee of JMA Consulting & CiviCRM; Kevin Cristiano of Tadpole Collective
security/core#136