CIVI-SA-2019-12: SQLI in "country", et al

Published
2019-05-15 09:00
Written by

When processing country, state, province, or county references, some values were not properly validated - which enabled a SQL-injection (SQLI) vulnerability.

 

Security Risk
Critical
Vulnerability
SQL Injection
Affected Versions

CiviCRM Versions 5.13.0 and earlier

Fixed Versions

CiviCRM version 5.13.4 and 5.7.6

Solutions

Upgrade to the latest version of CiviCRM

Credits

Tim Otten of CiviCRM Core Team for reporting the issue.

Seamus Lee of Australian Greens for fixing the issue.

References

security/core#49