PYSEC-2010-16

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/moin/PYSEC-2010-16.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2010-16
Aliases
Published
2010-08-05T13:22:00Z
Modified
2024-05-01T16:41:22.253603Z
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) Page.py, (2) PageEditor.py, (3) PageGraphicalEditor.py, (4) action/CopyPage.py, (5) action/Load.py, (6) action/RenamePage.py, (7) action/backup.py, (8) action/login.py, (9) action/newaccount.py, and (10) action/recoverpass.py.

References

Affected packages

PyPI / moin

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.8
Fixed
1.8.8
Introduced
1.9
Fixed
1.9.3

Affected versions

1.*

1.8.4
1.8.5
1.8.6
1.8.7
1.9.0
1.9.1
1.9.2