CIVI-SA-2023-11: Select2 XSS

Published
2023-09-06 12:00
Written by

Select2 is an auto-complete widget. In multiple places where CiviCRM uses Select2, it was vulnerable to stored cross-site scripting (XSS) attack.

(We believe that exploiting this requires that both the attacker and the victim have a high-level of access to the same CiviCRM deployment.)

Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM version 5.64.3 and earlier

Fixed Versions

CiviCRM version 5.64.4, 5.65.0 and 5.63.4 (ESR)

Publication Date
Solutions

Upgrade to the fixed version of CiviCRM

Credits

Jean-Marie Heitz of Uepal.
Coleman Watts of CiviCRM.
Seamus Lee of JMA Consulting/CiviCRM.

CVE
CVE-2016-10744