VulnerabilityModified
CVE-2017-5934
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
MEDIUM 6.1EPSS 1.94%
Does this matter?
Lower severity and a low EPSS score (1.94%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.94% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- moinmo/moinmoin · canonical/ubuntu linux · debian/debian linux · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00024.htmlMailing List, Third Party Advisory
- http://moinmo.in/SecurityFixesRelease Notes, Vendor Advisory
- https://github.com/moinwiki/moin-1.9/commit/70955a8eae091cc88fd9a6e510177e70289ec024Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00007.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3794-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4318Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-10/msg00024.htmlMailing List, Third Party Advisory
- http://moinmo.in/SecurityFixesRelease Notes, Vendor Advisory
- https://github.com/moinwiki/moin-1.9/commit/70955a8eae091cc88fd9a6e510177e70289ec024Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00007.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3794-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4318Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.