CVE-2016-7146
MEDIUMMoinmoin < 1.9.9 - XSS
Title source: ruleDescription
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.
References (4)
Scores
CVSS v3
6.1
EPSS
0.0025
EPSS Percentile
48.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
moinmo/moinmoin
pypi/moin
< 1.9.9PyPI
Timeline
Published
Nov 10, 2016
Tracked Since
Feb 18, 2026