CVE-2016-7148

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/11/2016
Last modified:
12/04/2025

Description

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moinmo:moinmoin:1.9.8:*:*:*:*:*:*:*