MoinMoin Multiple cross-site scripting (XSS) vulnerabilities

Description

Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Not specified
Published (advisory)
2022-05-01 17:47:36 UTC
Updated
2024-05-24 05:03:38 UTC
GitHub reviewed
2024-05-14 20:41:15 UTC
NVD published
2007-02-08

EPSS Score

Score Percentile
1.22% 78.82%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
pip moin < 1.5.7 1.5.7

References

cvelogic Threat Intelligence