- Nodequeue 1.x versions prior to 1.x-2.2.0
This module enables you to collect nodes in an arbitrarily ordered list.
Nodequeue's JavaScript can be leveraged to insert HTML from attacker-controlled JSON data. This is exploitable if user-submitted "Filtered HTML" content is displayed on a page where nodequeue.js is loaded.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "manipulate queues".
Upgrade your site to the most recent version of Nodequeue. Download available on the Nodequeue release page.
See the update instructions, if needed.
- Vijaya Chandran Mani
- Jen Lampton of the Backdrop CMS Security Team
- Greg Knaddison of the Drupal Security Team
- Michael Hess of the Drupal Security Team
- Jen Lampton of the Backdrop CMS Security Team
- Gregory Netsas of the Backdrop CMS Security Team