CVE-2012-4404

Moinmoin < 1.9.5 - Access Control

Title source: rule

Description

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

Scores

EPSS 0.0099
EPSS Percentile 76.6%

Classification

CWE
CWE-264
Status draft

Affected Products (6)

moinmo/moinmoin
moinmo/moinmoin
moinmo/moinmoin
moinmo/moinmoin
moinmo/moinmoin
pypi/moin < 1.9.5PyPI

Timeline

Published Sep 10, 2012
Tracked Since Feb 18, 2026