Security Risk: 
Critical
Vulnerability: 
Cross Site Scripting
Affected Versions: 

CiviCRM versions prior to 4.7.26 and 4.6.33

Fixed Versions: 

CiviCRM version 4.7.26 and 4.6.33

Publication Date: 
Wednesday, November 1, 2017
Description: 

The form processing for the dedupe rules listing page did not properly validate the contact type variable that is passed through in the URL parameters. This potentially allowed for XSS to occur. This has been fixed to allow for only known contact types to be passed in. 

Solutions: 

Upgrade to the latest version of CiviCRM

  • 4.7.26
  • 4.6.33

or later

If you cannot upgrade you should 

Credits: 

Sean Madsen of Left Join Labs for Reporting the issue

Seamus Lee of Australian Greens for Fixing the issue

References: