Home
» GitHub Advisories
» GHSA-m84w-vgwf-p893
Description
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.
Basic information
Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
—
Source code
Not specified
Published (advisory)
2022-05-01 17:47:36 UTC
Updated
2024-05-24 05:03:38 UTC
GitHub reviewed
2024-05-14 20:41:15 UTC
NVD published
2007-02-08
EPSS Score
Score
Percentile
1.22%
78.82%
CVSS Scores
No CVSS scores in this advisory.
CWEs
CWE id
Name
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected packages (1)
Vulnerable version ranges and first patched releases as published by GitHub.
Ecosystem
Package
Vulnerable range
First patched
Vulnerable functions
pip
moin
< 1.5.7
1.5.7
—
cvelogic
Threat Intelligence