This module enables you to create an entityqueue based on a taxonomy.
The module did not properly use Drupal's database API when querying the database with user supplied values, allowing an attacker to send a specially crafted request to modify the query or potentially perform additional queries.
This vulnerability is mitigated by the fact that an attacker must have a role with the "administer entity queue taxonomy" permission.
Install the latest version:
- If you use the Taxonomy Entity Queue module for Drupal 7.x, upgrade to Taxonomy Entity Queue 7.x-1.1
Also see the Taxonomy Entity Queue project page.
- Michael Hess of the Drupal Security Team