CIVI-SA-2024-04: Copy / Clone Actions (CSRF)
CIVI-SA-2024-04: Copy / Clone Actions (CSRF)In some parts of the CiviCRM administrative interface, the "Copy" or "Clone" actions are vulnerable to cross-site request forgery.dev-team2024-10-16 -...
View ArticleCIVI-SA-2024-05: Multiple AJAX End-Points (CSRF)
CIVI-SA-2024-05: Multiple AJAX End-Points (CSRF)Multiple AJAX end-points may be vulnerable to Cross Site Request Forgery.This release updates a large number of older end-points originating circa...
View ArticleCIVI-SA-2024-06: Source and Name Fields (XSS)
CIVI-SA-2024-06: Source and Name Fields (XSS)There are stored cross-site scripting vulnerabilities involving some variations of the "name" and "source" fields in certain backend...
View ArticleCIVI-SA-2024-07: Symbolic Link Cleanup
CIVI-SA-2024-07: Symbolic Link CleanupThe helper function CRM_Utils_File::cleanDir() is used to cleanup certain data folders. In some situations, it might be tricked into deleting additional files...
View ArticleCIVI-SA-2024-08: PhpSpreadsheet
CIVI-SA-2024-08: PhpSpreadsheetThe bundled library "PhpSpreadsheet" has issued multiple security advisories.dev-team2024-10-16 - 12:00Security RiskCriticalVulnerabilityOtherAffected VersionsCiviCRM...
View ArticleCIVI-PSA-2024-01: wkhtmltopdf (EOL)
CIVI-PSA-2024-01: wkhtmltopdf (EOL)CiviCRM generates *.pdf files with the assistance of a PDF engine. It is compatible with multiple engines, including the default DOMPDF and the alternative...
View ArticleCiviCRM Support for D7
CiviCRM Support for D7josh2024-12-05 - 06:32 (logged-in users can click thumbs up if they thought this blog post was useful) (login to vote or to comment) Save
View ArticleCiviCRM on Drupal 7 is Reaching End of Life: What Are Your Next Steps?
CiviCRM on Drupal 7 is Reaching End of Life: What Are Your Next Steps?pkeogan2024-12-08 - 04:26 (logged-in users can click thumbs up if they thought this blog post was useful) (login to vote or to...
View ArticleBringing in the New Year with what NOT to do
Bringing in the New Year with what NOT to doStoob2025-01-01 - 11:48
View Article