Junglewise Threat Intelligence
CVE-2016-7148: PYSEC-2016-31 - MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross
CVE-2016-7148 · Severity: low · CVSS 3 · Published 2016-11-10
Technologies: moin (PyPI). Vendors: PyPI.
Executive brief
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.