Updated November 22.
This module enables you to collect nodes in an arbitrarily ordered list.
Nodequeue's JavaScript can be leveraged to insert HTML from attacker-controlled JSON data. This is exploitable if user-submitted "Filtered HTML" content is displayed on a page where nodequeue.js is loaded.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "manipulate queues".
Original advisory:
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported
Install the latest version:
- If you use the Nodequeue module for Drupal 7.x, upgrade to Nodequeue 7.x-2.2
Also see the Nodequeue project page.
Original solution
If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#procedure---own-project---unsupported in full.
- Greg Knaddison of the Drupal Security Team
- Michael Hess of the Drupal Security Team