Safety vulnerability ID: 36448
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Moin 1.9.9 includes a fix for CVE-2016-7148: MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
Latest version: 1.9.11
MoinMoin 1.9.11 is an easy to use, full-featured and extensible wiki software package
Fixes:
* security: fix XSS in AttachFile view (multifile related) CVE-2016-7148
* security: fix XSS in GUI editor's attachment dialogue CVE-2016-7146
* security: fix XSS in GUI editor's link dialogue CVE-2016-9119
* catch IOError for zipfile errors (sometimes triggered by zipfile.is_zipfile
false positives, see http://bugs.python.org/issue28494 ).
Other changes:
* update moin.spec, setup.py: py27 only
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application