MoinMoin Cross-site scripting (XSS) vulnerability in the antispam feature

Description

Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Not specified
Published (advisory)
2022-05-02 03:14:13 UTC
Updated
2024-05-14 20:41:19 UTC
GitHub reviewed
2024-05-14 20:41:18 UTC
NVD published
2009-01-27

EPSS Score

Score Percentile
0.68% 71.50%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
pip moin < 1.8.2 1.8.2

References

cvelogic Threat Intelligence