CVE-2016-7146

MEDIUM

MoinMoin 1.9.8 - Cross-Site Scripting via FCKeditor Attachment Dialog

Title source: llm
STIX 2.1

Description

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-3137-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94259
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3715
Exploit, Third Party Advisory x_refsource_misc
https://www.curesec.com/blog/article/blog/MoinMoin-198-XSS-175.html

Scores

CVSS v3 6.1
EPSS 0.0119
EPSS Percentile 64.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
moinmo/moinmoin 1.9.8
pypi/moin 1.9.8 - 1.9.9PyPI
Published Nov 10, 2016
Tracked Since Feb 18, 2026