CVE-2010-0828

MoinMoin 1.8.7 and 1.9.2 - Authenticated Cross-Site Scripting via Despam Action Module

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a crafted URI.

References (18)

Core 18
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0767
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57435
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39267
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39110
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038574.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2024
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0834
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39284
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038490.html
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=575995
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39190
Exploit, Patch x_refsource_confirm
http://hg.moinmo.in/moin/1.9/rev/6e603e5411ca
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39188
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0831
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-925-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038706.html

Scores

EPSS 0.0224
EPSS Percentile 81.0%

Details

CWE
CWE-79
Status published
Products (3)
moinmo/moinmoin 1.8.7
moinmo/moinmoin 1.9.2
pypi/moin 1.9.0 - 1.9.3PyPI
Published Apr 05, 2010
Tracked Since Feb 18, 2026