Project: 
Date: 
2018-July-11
Vulnerability: 
Cross Site Scripting
Description: 

This theme provides Drupal users with many advanced features including 20 Different Color Styles, 30 User Regions, Custom Block Theme Templates, Suckerfish Menus, Icon Support, Advanced Page Layout Options, Simple Configuration, Custom Typography...

The theme doesn't sufficiently sanitize user input.

This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.

Solution: 

Install the latest version:

Also see the Tapestry project page.

Reported By: 
Fixed By: 
Coordinated By: