CVE-2020-25074
CRITICALMoinmoin < 1.9.10 - Path Traversal
Title source: ruleDescription
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
References (4)
Scores
CVSS v3
9.8
EPSS
0.1281
EPSS Percentile
93.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-22
Status
published
Affected Products (4)
moinmo/moinmoin
< 1.9.10
debian/debian_linux
debian/debian_linux
pypi/moin
< 1.9.11PyPI
Timeline
Published
Nov 10, 2020
Tracked Since
Feb 18, 2026