CIVI-SA-2017-11 XSS in dedupe rules

Published
2017-11-01 09:00
Written by

The form processing for the dedupe rules listing page did not properly validate the contact type variable that is passed through in the URL parameters. This potentially allowed for XSS to occur. This has been fixed to allow for only known contact types to be passed in. 

Security Risk
Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM versions prior to 4.7.26 and 4.6.33

Fixed Versions

CiviCRM version 4.7.26 and 4.6.33

Solutions

Upgrade to the latest version of CiviCRM

  • 4.7.26
  • 4.6.33

or later

If you cannot upgrade you should 

Credits

Sean Madsen of Left Join Labs for Reporting the issue

Seamus Lee of Australian Greens for Fixing the issue

References