MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.
CVSS Details
- CVSS 3.1 Base Score: 8.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-moin | Nov 11, 2020 | Nov 11, 2020 | |
| Freebsd | freebsd-upgrade-package-moinmoin | Jan 19, 2021 | Jan 18, 2021 | |
| Suse | — | suse-upgrade-moinmoin-wiki | Dec 11, 2020 | Nov 11, 2020 |
| Ubuntu | ubuntu-upgrade-python-moinmoin | Mar 22, 2023 | Nov 11, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub