The form processing for the dedupe rules listing page did not properly validate the contact type variable that is passed through in the URL parameters. This potentially allowed for XSS to occur. This has been fixed to allow for only known contact types to be passed in.
CiviCRM versions prior to 4.7.26 and 4.6.33
CiviCRM version 4.7.26 and 4.6.33
Upgrade to the latest version of CiviCRM
If you cannot upgrade you should
Sean Madsen of Left Join Labs for Reporting the issue
Seamus Lee of Australian Greens for Fixing the issue