CVE-2020-15275
Summary
| CVE | CVE-2020-15275 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-11 16:15:00 UTC |
| Updated | 2022-10-18 20:47:00 UTC |
| Description | MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request from GHSA-4q96-6xhq-ff43 · moinwiki/moin-1.9@31de913 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| malicious SVG attachment causing stored XSS vulnerability · Advisory · moinwiki/moin-1.9 · GitHub | CONFIRM | github.com | Third Party Advisory |
| Release MoinMoin Wiki 1.9.11 · moinwiki/moin-1.9 · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| advisory.checkmarx.net/advisory/CX-2020-4285 | MISC | advisory.checkmarx.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.