When using re-colorable themes, color inputs are not sanitized. Malicious color values can be used to insert arbitrary CSS and script code. Successful exploitation requires the “Administer themes” permission.
https://drupal.org/node/1168756
This vulnerability affects the following application versions:
- Drupal 7.0