CVE-2011-1058: XSS
Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/textrst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the refuri attribute. NOTE: some of these details are obtained from third party information.
Other sources
Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/textrst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the refuri attribute. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2011-1058?
CVE-2011-1058 is a cross-site scripting (XSS) vulnerability in the reStructuredText parser of MoinMoin before version 1.9.3, which allows attackers to inject malicious scripts via a javascript: URL in the refuri attribute.
What are the affected versions for CVE-2011-1058?
Affected versions for CVE-2011-1058 include all versions of MoinMoin prior to 1.9.3.
What is the severity of CVE-2011-1058?
CVE-2011-1058 is classified as a medium severity vulnerability due to its potential to allow attackers to execute arbitrary scripts.
How do I fix CVE-2011-1058?
To fix CVE-2011-1058, update MoinMoin to version 1.9.3 or later.
Can CVE-2011-1058 affect my MoinMoin installation?
If you are running a version of MoinMoin prior to 1.9.3, you are at risk of CVE-2011-1058 and should take immediate action.