This SA only affects users of the CiviCase v5 extension. In versions prior to 1.1, the extension did not properly escape the "Subject" field when using the in-place editor.
- CiviCase v5 extension ("org.civicrm.civicase") prior to v1.1
- CiviCase v5 extension ("org.civicrm.civicase") v1.1
Upgrade to the latest version of the "org.civicrm.civicase" extension
Daniel Compton of Armadillo Sec Ltd for reporting the issue
Seamus Lee of Australian Greens for fixing the issue
security/core#64