The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.
| Software | From | Fixed in |
|---|---|---|
| civicrm / civicrm | 4.2.5 | 4.2.5.x |
| civicrm / civicrm | 4.3.1 | 4.3.1.x |
| civicrm / civicrm | 4.2.8 | 4.2.8.x |
| civicrm / civicrm | 4.2.7 | 4.2.7.x |
| civicrm / civicrm | 4.3.0 | 4.3.0.x |
| civicrm / civicrm | 4.2.1 | 4.2.1.x |
| civicrm / civicrm | 4.2.0 | 4.2.0.x |
| civicrm / civicrm | 4.2.4 | 4.2.4.x |
| civicrm / civicrm | 4.3.2 | 4.3.2.x |
| civicrm / civicrm | 4.2.2 | 4.2.2.x |
| civicrm / civicrm | 4.2.6 | 4.2.6.x |
| civicrm / civicrm | 4.3.3 | 4.3.3.x |
| civicrm / civicrm | 4.2.9 | 4.2.9.x |