Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
Fix XSS issue - sanitisation of rot13 decoded text. Requires admin access or admin (mis)configuration of text filters to allow Full HTML text format for non-admins (or equivalent) and other configuration steps before this issue can be exploited.