CIVI-SA-2015-011: Reflected XSS in Error Message

Published
2015-11-03 12:40
Written by

This release addresses an issue where it was possible to deliver XSS by directing a user to a CiviCRM URL which triggered a fatal error. The issue has been addressed by correctly escaping output from CiviCRM's fatal error handler.

For more information about this type of vulnerability, see OWASP's page on Cross Site Scripting.

 

Security Risk
Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM v4.3 - v4.6

Fixed Versions

CiviCRM v4.4.20, v4.6.10

Solutions

Any ONE of the following:

  • Upgrade to CiviCRM v4.4.20+ or v4.6.10+
  • Apply change ed6a28a1.
Credits
  • Marcin Piosek

  • Tim Otten (CiviCRM)

  • Eileen McNaughton (Fuzion)