CiviCRM Version prior to 4.7.26 and 4.6.33
CiviCRM Versions 4.7.26 AND 4.6.33
CiviCRM used to output the Search criteria in the description field without any escaping. Given that certain parts of the criteria in a search form can be passed through as URL parameters, there was the possibility of XSS scripting coming in and not being properly escaped when displayed.
Update to the latest version of CiviCRM:
Or apply the following patch https://github.com/civicrm/civicrm-core/pull/11001
Sean Madsen of Left Join Labs for Reporting and Fixing the issue