PT-2020-5775 · Moinmoin+2 · Moinmoin+2
Catarina Leite
·
Published
2020-11-01
·
Updated
2022-10-18
·
CVE-2020-15275
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
MoinMoin versions prior to 1.9.11
Description:
The issue is related to the insufficient protection measures of web page structures in the MoinMoin wiki platform, specifically concerning the upload of SVG files. An attacker with
write permissions can upload an SVG file containing malicious javascript, which will be executed in a user's browser when viewing the SVG file. This can impact the integrity of the data.Recommendations:
For versions prior to 1.9.11, upgrade to MoinMoin Wiki 1.9.11, which contains the necessary fixes. As a temporary workaround, consider restricting
write permissions to only trusted users. Additionally, implementing a Content Security Policy in the web server might be a possible workaround, but upgrading to a patched version is strongly advised.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moinmoin
Suse
Ubuntu