CVE-2010-2487: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) Page.py, (2) PageEditor.py, (3) PageGraphicalEditor.py, (4) action/CopyPage.py, (5) action/Load.py, (6) action/RenamePage.py, (7) action/backup.py, (8) action/login.py, (9) action/newaccount.py, and (10) action/recoverpass.py.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) Page.py, (2) PageEditor.py, (3) PageGraphicalEditor.py, (4) action/CopyPage.py, (5) action/Load.py, (6) action/RenamePage.py, (7) action/backup.py, (8) action/login.py, (9) action/newaccount.py, and (10) action/recoverpass.py.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2487?
CVE-2010-2487 is considered to have a medium severity rating due to its cross-site scripting vulnerabilities.
How do I fix CVE-2010-2487?
To fix CVE-2010-2487, upgrade to MoinMoin version 1.8.8 or later for the 1.8.x branch and 1.9.3 or later for the 1.9.x branch.
Which versions are affected by CVE-2010-2487?
The affected versions by CVE-2010-2487 include MoinMoin 1.7.3 and earlier, all versions before 1.8.8 in the 1.8.x line, and all versions before 1.9.3 in the 1.9.x line.
What type of vulnerability is CVE-2010-2487?
CVE-2010-2487 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2010-2487 be exploited remotely?
Yes, CVE-2010-2487 can be exploited remotely by attackers to perform cross-site scripting attacks.