CVE-2008-1099

MoinMoin < 1.5.8 - Unauthenticated Protected Page Access via _macro_Getval

Title source: llm
STIX 2.1

Description

_macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages.

References (13)

Core 13
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30031
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33755
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200803-27.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28177
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29262
Various Sources x_refsource_confirm
http://moinmo.in/SecurityFixes
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41038
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29444
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/716-1/
Various Sources x_refsource_confirm
http://hg.moinmo.in/moin/1.5/rev/4a7de0173734
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1514

Scores

EPSS 0.0200
EPSS Percentile 78.8%

Details

CWE
CWE-264
Status published
Products (2)
moinmoin/moinmoin < 1.5.8
pypi/moin 0PyPI
Published Mar 05, 2008
Tracked Since Feb 18, 2026