The Workflow module enables you to create arbitrary Workflows, and assign them to Entities.
The module doesn't sufficiently escape HTML in the field settings leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer nodes" and "administer workflow".
Install the latest version:
- If you use the Workflow module for Drupal 7.x, upgrade to Workflow 7.x-2.12
- Roberto Mariani
- David Snopek of the Drupal Security Team
- John Voskuilen
- Sarah Hood
- Greg Knaddison of the Drupal Security Team
- Michael Hess of the Drupal Security Team