CVE-2017-5934

Published: 31 December 2017

Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Priority

Medium

CVSS 3 base score: 6.1

Status

Package Release Status
moin
Launchpad, Ubuntu, Debian
Upstream
Released (1.9.10)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1.9.9-1ubuntu1.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1.9.8-1ubuntu1.16.04.2)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was released [1.9.7-1ubuntu2.2])