PT-2008-3463 · Moinmoin · Moinmoin

Published

2008-04-24

·

Updated

2022-05-01

·

CVE-2008-1937

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MoinMoin versions prior to 1.6.3
Description The issue is related to the user form processing in MoinMoin, specifically in the userform.py module. When Access Control Lists (ACLs) or a non-empty superusers list are used, the software does not properly manage users. This allows remote attackers to gain privileges.
Recommendations For versions prior to 1.6.3, update to version 1.6.3 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1937
GHSA-RQXP-6926-HPHR
PYSEC-2008-12

Affected Products

Moinmoin