CVE-2009-0312: XSS
Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mointo a version that resolves this vulnerability.Fixed in 1.9.9-1+deb10u1 - Upgrade
Upgrade
pip/mointo a version that resolves this vulnerability.Fixed in 1.8.2
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0312?
CVE-2009-0312 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2009-0312?
To fix CVE-2009-0312, upgrade to MoinMoin version 1.9.9-1+deb10u1 or version 1.8.2.
What systems are affected by CVE-2009-0312?
CVE-2009-0312 affects MoinMoin versions 1.7.x and 1.8.1.
Can CVE-2009-0312 allow remote attacks?
Yes, CVE-2009-0312 allows remote attackers to inject arbitrary web scripts or HTML.
Does CVE-2009-0312 have a known exploit?
There are no specific known exploits for CVE-2009-0312, but it remains a risk due to the nature of XSS vulnerabilities.