Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 22.04 CiviCRM Important JavaScript Execution Risk USN-8242-1

Ubuntu Large Esm H500
CiviCRM could be made to run malicious JavaScript in the user's browser if it received specially crafted input.
==========================================================================
Ubuntu Security Notice USN-8242-1
May 07, 2026

civicrm vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

CiviCRM could be made to run malicious JavaScript in the user's browser
if it received specially crafted input.

Software Description:
- civicrm: Constituent relationship management solution

Details:

Takuya Aramaki discovered that Smarty, vendored in CiviCRM, did not
properly escape JavaScript code. An attacker could possibly use this issue
to conduct a cross-site scripting attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
  civicrm-common                  5.33.2+dfsg1-1ubuntu1+esm1
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  civicrm-common                  5.21.2+dfsg-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  civicrm-common                  4.7.30+dfsg-1ubuntu1+esm1
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  civicrm-common                  4.7.1+dfsg-2ubuntu1+esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8242-1
  CVE-2023-28447

Ubuntu 22.04 CiviCRM Important JavaScript Execution Risk USN-8242-1

ubuntu
Calendar Grey May 7, 2026
Dist Ubuntu Esm H88
CiviCRM on Ubuntu may run malicious JavaScript due to insufficient escaping, risking user data. Update recommended.
CiviCRM could be made to run malicious JavaScript in the user's browser if it received specially crafted input.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: CiviCRM could be made to run malicious JavaScript in the user's browser if it received specially crafted input. Software Description: - civicrm: Constituent relationship management solution Details: Takuya Aramaki discovered that Smarty, vendored in CiviCRM, did not properly escape JavaScript code. An attacker could possibly use this issue to conduct a cross-site scripting attack.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS civicrm-common 5.33.2+dfsg1-1ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS civicrm-common 5.21.2+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS civicrm-common 4.7.30+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS civicrm-common 4.7.1+dfsg-2ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8242-1

CVE-2023-28447

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8242-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here