Date: 
2018-July-18
Vulnerability: 
SQL Injection
Description: 

This module enables you to create an entityqueue based on a taxonomy.

The module did not properly use Drupal's database API when querying the database with user supplied values, allowing an attacker to send a specially crafted request to modify the query or potentially perform additional queries.

This vulnerability is mitigated by the fact that an attacker must have a role with the "administer entity queue taxonomy" permission.

Solution: 

Install the latest version:

Also see the Taxonomy Entity Queue project page.

Reported By: 
Coordinated By: