CVE-2022-29251 – org.xwiki.platform:xwiki-platform-flamingo-theme-ui
Package
Manager: maven
Name: org.xwiki.platform:xwiki-platform-flamingo-theme-ui
Vulnerable Version: >=0 <12.10.11 || >=13.0.0 <13.4.7 || >=13.5.0 <13.10.3
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.01833 pctl0.82216
Details
Cross-site Scripting in the Flamingo theme manager ### Impact We found a possible XSS vector in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the "newThemeName" form field. ### Patches The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, 13.10.3. ### Workarounds The easiest workaround is to edit the wiki page `FlamingoThemesCode.WebHomeSheet` (with wiki editor) and change the line ``` <input type="hidden" name="newThemeName" id="newThemeName" value="$request.newThemeName" /> ``` into ``` <input type="hidden" name="newThemeName" id="newThemeName" value="$escapetool.xml($request.newThemeName)" /> ``` ### References * https://jira.xwiki.org/browse/XWIKI-19294 * https://github.com/xwiki/xwiki-platform/commit/bd935320bee3c27cf7548351b1d0f935f116d437 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security mailing list](mailto:security@xwiki.org)
Metadata
Created: 2022-05-25T22:40:57Z
Modified: 2022-06-08T17:31:04Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vmhh-xh3g-j992/GHSA-vmhh-xh3g-j992.json
CWE IDs: ["CWE-116", "CWE-79", "CWE-80"]
Alternative ID: GHSA-vmhh-xh3g-j992
Finding: F008
Auto approve: 1