A user with permission to manage File uploads via APIv4 can escalate to executing arbitrary PHP files.
CiviCRM v6.2.0 - 6.12.0
CiviCRM v6.12.1, v6.10.3 (ESR), and later
Any ONE of the following will mitigate the vulnerability:
- Upgrade to a fixed version of CiviCRM, or...
- Revoke the permission
access uploaded filesfrom non-administrators
Lassi (lassitemp@proton.me), Coleman Watts (CiviCRM), Tim Otten (CiviCRM), Seamus Lee (JMA Consulting)
