When Contact entity fields are added to forms, the display name label wasn't properly sanitised.
CiviCRM versions 5.10.2 and earlier
CiviCRM version 5.10.3 and 5.7.4
Upgrade to the latest CiviCRM Version
Sean Colsen of Left Join Labs for reporting the issues
Seamus Lee of Australian Greens for fixing the issue.
security/core#9