Junglewise Threat Intelligence

CVE-2011-1058: PYSEC-2011-6 - Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils

CVE-2011-1058 · Severity: low · CVSS 3.1 · Published 2011-02-22

Technologies: moin (PyPI). Vendors: PyPI.

Executive brief

Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the refuri attribute. NOTE: some of these details are obtained from third party information.

Affected products

  • PyPI moin

Related threats