PT-2020-5775 · Moinmoin+2 · Moinmoin+2

Catarina Leite

·

Published

2020-11-01

·

Updated

2022-10-18

·

CVE-2020-15275

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: MoinMoin versions prior to 1.9.11
Description: The issue is related to the insufficient protection measures of web page structures in the MoinMoin wiki platform, specifically concerning the upload of SVG files. An attacker with write permissions can upload an SVG file containing malicious javascript, which will be executed in a user's browser when viewing the SVG file. This can impact the integrity of the data.
Recommendations: For versions prior to 1.9.11, upgrade to MoinMoin Wiki 1.9.11, which contains the necessary fixes. As a temporary workaround, consider restricting write permissions to only trusted users. Additionally, implementing a Content Security Policy in the web server might be a possible workaround, but upgrading to a patched version is strongly advised.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-01734
CVE-2020-15275
DLA-2446-1
DSA-4787-1
GHSA-4Q96-6XHQ-FF43
OPENSUSE-SU-2020:1966-1
OPENSUSE-SU-2020:1998-1
OPENSUSE-SU-2020_1966-1
PYSEC-2020-241
USN-4629-1

Affected Products

Moinmoin
Suse
Ubuntu