CIVI-SA-2018-03: Reflected XSS in Error Message

Publicat
2018-07-18 09:00
Written by

In some scenarios where an error message incorporates user-supplied text, a malicious input could become part of the response and lead to cross-site scripting.

Security Risk
Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM versions 5.3.0 and 4.6.37 (and earlier)

Fixed Versions

CiviCRM version 5.3.1 and 4.6.38 (and later)

Solutions

Upgrade to the latest version of CiviCRM

Credits

Patrick Figel of Greenpeace for reporting the issue.

Sean Madsen of Left Join Labs for fixing the issue.

References

security/core#2

security/core#3