High severityNVD Advisory· Published May 25, 2022· Updated Apr 23, 2025
Cross-site Scripting in the Flamingo theme manager
CVE-2022-29251
Description
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the FlamingoThemesCode.WebHomeSheet wiki page related to the "newThemeName" form field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page FlamingoThemesCode.WebHomeSheet (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.xwiki.platform:xwiki-platform-flamingo-theme-uiMaven | < 12.10.11 | 12.10.11 |
org.xwiki.platform:xwiki-platform-flamingo-theme-uiMaven | >= 13.0.0, < 13.4.7 | 13.4.7 |
org.xwiki.platform:xwiki-platform-flamingo-theme-uiMaven | >= 13.5.0, < 13.10.3 | 13.10.3 |
Affected products
2- Range: >= 6.2.4, < 12.10.11
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-vmhh-xh3g-j992ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-29251ghsaADVISORY
- github.com/xwiki/xwiki-platform/commit/bd935320bee3c27cf7548351b1d0f935f116d437ghsax_refsource_MISCWEB
- github.com/xwiki/xwiki-platform/security/advisories/GHSA-vmhh-xh3g-j992ghsax_refsource_CONFIRMWEB
- jira.xwiki.org/browse/XWIKI-19294ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.