CIVI-SA-2020-03: PHP Code Execution via Phar Deserialization

Published
2020-04-15 12:00
Written by

Backend users may be able to upload and execute a maliciously crafted "PHAR" file.

The "PharExtensionInterceptor" library from Typo3 addresses this problem. Many projects - including the current Drupal and Joomla releases - already activate this protection and are already secure. However, some environments - such as WordPress - do not have it. This update extends the protection to all CiviCRM-supported environments.

Progress on the civicrm.org Drupal8 upgrade

Published
2020-04-05 16:25
Written by
bgm

Back in September 2019, we had announced a plan to upgrade the content management system (CMS) running the civicrm.org website, as well as plans to make civicrm.org available in many languages. Today I'm happy to announce that we have reached a major milestone: most of the static content, user logins, blogs and many CiviCRM forms are now being served from Drupal8.

(logged-in users can click thumbs up if they thought this blog post was useful) (login to vote or to comment)

Join us at CiviCon

CiviCon brings together prospective and current end-users, administrators and developers of CiviCRM for content-rich discussions, lectures and networking. Sharpen your skills and get involved in the community.

If you're looking for a one-day event in cities around the world, check out our upcoming CiviCamps.

Trademark

CiviCRM Trademark & Brand Usage Policy

The CiviCRM trademark policy and brand usage policy are designed to foster growth and encourage responsible use without unnecessary burden. Both policies have been developed with the following goals in mind: