Ahmed Saad has brought to our attention a creative way to enter malicious HTML content. Upon further investigation we found that interpretation of broken HTML/SGML and various quirks in interpretation of correctly formed, but non-sensical attribute values by various browsers also allows entering malicious HTML content. These can lead to XSS attacks.
Vendor Status:
Drupal as issued an update for this vulnerablity.