Application: Drupal Project Issue Tracking Module
Affected Version: before 2008-01-30, 5.x-1.2 and earlier, 4.7.x-2.6 and earlier, and 4.7.x-1.6 and earlier.
Vendor’s URL: http://drupal.org/project/project_issue
Bug Type: Cross Site Scripting and File Inclusion
Risk Level: Critical
Solution:
Update to version 5.x-2.0, 5.x-1.3, 4.7.x-2.7, or 4.7.x-1.7.
