Nodequeue - Critical - Cross site scripting - BACKDROP-SA-CONTRIB-2019-013
This module enables you to collect nodes in an arbitrarily ordered list.
Nodequeue's JavaScript can be leveraged to insert HTML from attacker-controlled JSON data. This is exploitable if user-submitted "Filtered HTML" content is displayed on a page where nodequeue.js is loaded.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "manipulate queues".
- Nodequeue 1.x versions prior to 1.x-2.2.0