VYPR
High severityNVD Advisory· Published May 25, 2022· Updated Apr 23, 2025

Cross-site Scripting in the Flamingo theme manager

CVE-2022-29251

Description

XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the FlamingoThemesCode.WebHomeSheet wiki page related to the "newThemeName" form field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page FlamingoThemesCode.WebHomeSheet (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.xwiki.platform:xwiki-platform-flamingo-theme-uiMaven
< 12.10.1112.10.11
org.xwiki.platform:xwiki-platform-flamingo-theme-uiMaven
>= 13.0.0, < 13.4.713.4.7
org.xwiki.platform:xwiki-platform-flamingo-theme-uiMaven
>= 13.5.0, < 13.10.313.10.3

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.