CVE-2016-7148 β€” Cross-site Scripting in Moinmoin

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 53.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 10
Latest updateMay 17

Description

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

β–ΆNVDmoinmo/moinmoin1.9.8

πŸ”΄Vulnerability Details

3
GHSA
MoinMoin Cross-site Scripting (XSS) vulnerability↗2022-05-17
β–Ά
OSV
MoinMoin Cross-site Scripting (XSS) vulnerability↗2022-05-17
β–Ά
OSV
CVE-2016-7148: MoinMoin 1β†—2016-11-10
β–Ά

πŸ“‹Vendor Advisories

1
Ubuntu
MoinMoin vulnerabilities↗2016-11-23
β–Ά

πŸ’¬Community

3
Bugzilla
CVE-2016-7146 CVE-2016-7148 moin: Javascript injection via page creation [fedora-all]β†—2016-11-14
β–Ά
Bugzilla
CVE-2016-7146 CVE-2016-7148 moin: Javascript injection via page creation↗2016-11-14
β–Ά
Bugzilla
CVE-2016-7146 CVE-2016-7148 moin: Javascript injection via page creation [epel-all]β†—2016-11-14
β–Ά
CVE-2016-7148 β€” Cross-site Scripting in Moinmo Moinmoin | cvebase