When loading dashboard dashlets, the system did not properly ensure that the title of the dashlets was properly escaped.
- CiviCRM before 5.19.2 and before 5.13.7
- CiviCRM 5.19.2 and 5.13.7
Upgrade to the latest version of CiviCRM
Daniel Compton of Armadillo Sec Ltd for reporting the issue
Patrick Figel of Greenpeace CEE and Seamus Lee of Australian Greens for fixing the issue
security/core#65