PYSEC-2020-241

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/moin/PYSEC-2020-241.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2020-241
Aliases
Published
2020-11-11T16:15:00Z
Modified
2023-11-01T05:44:05.432652Z
Summary
[none]
Details

MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.

References

Affected packages

PyPI / moin

Package

Affected ranges

Type
GIT
Repo
https://github.com/moinwiki/moin-1.9
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.11

Affected versions

1.*

1.8.4
1.8.5
1.8.6
1.8.7
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
1.9.10