Veröffentlicht
2026-03-18 12:00
Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions
CiviCRM v6.12.0 and earlier
Fixed Versions
CiviCRM v6.12.1, v6.10.3 (ESR), and later
Publication Date
Solutions
Any ONE of the following will mitigate the vulnerability:
- Upgrade to a fixed version of CiviCRM, or...
- Revoke permission to work with account "batches" for non-administrators
Credits
Lassi (lassitemp@proton.me), Luke Stewart (Fuzion), Seamus Lee (JMA Consulting), Coleman Watts (CiviCRM)
