Security Risk: 
Critical
Vulnerability: 
SQL Injection
Affected Versions: 

CiviCRM versions 5.10.2 and earlier

Fixed Versions: 

CiviCRM Version 5.10.3 and 5.7.4

Publication Date: 
Wednesday, February 20, 2019
Description: 

When conducting a "Contact" search, the groups and tags parameters were vulerable to SQL injection.

Solutions: 

Upgrade to the latest CiviCRM Version

Credits: 

Patrick Figel of Greenpeace for reporting and fixing the issue

References: 

security/core#28