CVE-2020-15275
published 2020-11-11CVE-2020-15275: MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.73%
74.7th percentile
MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moinmo | moinmoin | < 1.9.11 | 1.9.11 |
| moinwiki | moin-1.9 | < 1.9.11 | 1.9.11 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_ubuntu8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-15275: MoinMoin is a wiki engine
osv·2020-11-11
CVE-2020-15275 CVE-2020-15275: MoinMoin is a wiki engine
MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.
OSV
moin vulnerabilities
osv·2020-11-11·CVSS 5.4
CVE-2020-25074 [MEDIUM] moin vulnerabilities
moin vulnerabilities
Michael Chapman discovered that MoinMoin incorrectly handled certain cache actions.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-25074)
Catarina Leite discovered that MoinMoin incorrectly handled certain SVG files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-15275)
GHSA
malicious SVG attachment causing stored XSS vulnerability
ghsa·2020-11-11
CVE-2020-15275 [MEDIUM] CWE-79 malicious SVG attachment causing stored XSS vulnerability
malicious SVG attachment causing stored XSS vulnerability
### Impact
An attacker with `write` permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki.
### Patches
Users are strongly advised to upgrade to a patched version.
MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.
### Workarounds
It is not advised to work around this, but to upgrade MoinMoin to a patched version.
That said, a work around via a Content Security Policy in the web server might be possible.
Also, it is of course helpful if you give `write` permissions (which include uploading attachments) only to trusted users.
### For more information
If you have any question
OSV
malicious SVG attachment causing stored XSS vulnerability
osv·2020-11-11
CVE-2020-15275 [MEDIUM] malicious SVG attachment causing stored XSS vulnerability
malicious SVG attachment causing stored XSS vulnerability
### Impact
An attacker with `write` permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki.
### Patches
Users are strongly advised to upgrade to a patched version.
MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.
### Workarounds
It is not advised to work around this, but to upgrade MoinMoin to a patched version.
That said, a work around via a Content Security Policy in the web server might be possible.
Also, it is of course helpful if you give `write` permissions (which include uploading attachments) only to trusted users.
### For more information
If you have any question
Ubuntu
MoinMoin vulnerabilities
vendor_ubuntu·2020-11-11·CVSS 8.7
CVE-2020-25074 [HIGH] MoinMoin vulnerabilities
Title: MoinMoin vulnerabilities
Summary: Several security issues were fixed in MoinMoin.
Michael Chapman discovered that MoinMoin incorrectly handled certain cache actions.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-25074)
Catarina Leite discovered that MoinMoin incorrectly handled certain SVG files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-15275)
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://advisory.checkmarx.net/advisory/CX-2020-4285https://github.com/moinwiki/moin-1.9/commit/31de9139d0aabc171e94032168399b4a0b2a88a2https://github.com/moinwiki/moin-1.9/releases/tag/1.9.11https://github.com/moinwiki/moin-1.9/security/advisories/GHSA-4q96-6xhq-ff43https://advisory.checkmarx.net/advisory/CX-2020-4285https://github.com/moinwiki/moin-1.9/commit/31de9139d0aabc171e94032168399b4a0b2a88a2https://github.com/moinwiki/moin-1.9/releases/tag/1.9.11https://github.com/moinwiki/moin-1.9/security/advisories/GHSA-4q96-6xhq-ff43
2020-11-11
Published