6.1
CVSSv3

CVE-2016-9119

Published: 30/01/2017 Updated: 03/02/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin prior to 1.9.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moinmo moinmoin

canonical ubuntu linux 16.10

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in MoinMoin ...
Several cross-site scripting vulnerabilities were discovered in moin, a Python clone of WikiWiki A remote attacker can conduct cross-site scripting attacks via the GUI editor's attachment dialogue (CVE-2016-7146), the AttachFile view (CVE-2016-7148) and the GUI editor's link dialogue (CVE-2016-9119) For the stable distribution (jessie), these pro ...
Debian Bug report logs - #844341 moin: CVE-2016-7148: XSS in AttachFile view (multifile related) Package: src:moin; Maintainer for src:moin is Steve McIntyre <93sam@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 14 Nov 2016 15:51:01 UTC Severity: serious Tags: fixed-upstream, patch, sec ...
Debian Bug report logs - #844340 moin: CVE-2016-7146: XSS in GUI editor's attachment dialogue Package: src:moin; Maintainer for src:moin is Steve McIntyre <93sam@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 14 Nov 2016 15:48:06 UTC Severity: serious Tags: fixed-upstream, patch, securi ...
Debian Bug report logs - #844338 moin: CVE-2016-9119: XSS in GUI editor's link dialogue Package: src:moin; Maintainer for src:moin is Steve McIntyre <93sam@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 14 Nov 2016 15:48:02 UTC Severity: serious Tags: fixed-upstream, patch, security, up ...