Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Catarina Leite

Researcher fromCheckmarx SCA AppSec team
#30111of 53,639
8.7Total CVSS
Vulnerabilities · 1
PT-2020-5775
8.7
2020-11-01
Moinmoin · Moinmoin · CVE-2020-15275
Name of the Vulnerable Software and Affected Versions: MoinMoin versions prior to 1.9.11 Description: The issue is related to the insufficient protection measures of web page structures in the MoinMoin wiki platform, specifically concerning the upload of SVG files. An attacker with `write` permissions can upload an SVG file containing malicious javascript, which will be executed in a user's browser when viewing the SVG file. This can impact the integrity of the data. Recommendations: For versions prior to 1.9.11, upgrade to MoinMoin Wiki 1.9.11, which contains the necessary fixes. As a temporary workaround, consider restricting `write` permissions to only trusted users. Additionally, implementing a Content Security Policy in the web server might be a possible workaround, but upgrading to a patched version is strongly advised.