MoinMoin improper sanitizes user profiles

Description

MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.

Basic information

Type
reviewed
Severity
high
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2022-05-02 06:14:38 UTC
Updated
2024-09-26 16:14:46 UTC
GitHub reviewed
2024-04-29 11:36:09 UTC
NVD published
2010-02-26

EPSS Score

Score Percentile
1.05% 77.51%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

Affected packages (2)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
pip moin < 1.8.7 1.8.7
pip moin >= 1.9, < 1.9.2 1.9.2

References

cvelogic Threat Intelligence