PT-2022-19499 · Xwiki · Xwiki Platform Flamingo Theme Ui

Thomas Mortagne

·

Published

2022-05-25

·

Updated

2022-06-07

·

CVE-2022-29251

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform Flamingo Theme UI versions prior to 12.10.11 XWiki Platform Flamingo Theme UI versions prior to 13.4.7 XWiki Platform Flamingo Theme UI versions prior to 13.10.3 XWiki Platform Flamingo Theme UI version 14.0-rc-1 and earlier
Description A possible cross-site scripting vector is present in the FlamingoThemesCode.WebHomeSheet wiki page related to the newThemeName form field. This issue can be exploited, allowing for potential malicious activities.
Recommendations For versions prior to 12.10.11, update to version 12.10.11 or later. For versions prior to 13.4.7, update to version 13.4.7 or later. For versions prior to 13.10.3, update to version 13.10.3 or later. For version 14.0-rc-1 and earlier, update to a version later than 14.0-rc-1. As a temporary workaround, edit the wiki page FlamingoThemesCode.WebHomeSheet and change the line <input type="hidden" name="newThemeName" id="newThemeName" value="$request.newThemeName" /> into <input type="hidden" name="newThemeName" id="newThemeName" value="$escapetool.xml($request.newThemeName)" />.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29251
GHSA-VMHH-XH3G-J992

Affected Products

Xwiki Platform Flamingo Theme Ui