CVE-2016-7148: XSS
Published Nov 10, 2016
·Updated
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
Affected Software
2 affected componentsFixes available
pip/moin<=1.9.8
1.9.9
MoinMoin=1.9.8
Event History
Nov 10, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:02 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-7148?
CVE-2016-7148 is classified as a moderate severity vulnerability due to its potential for JavaScript injection attacks.
2
How do I fix CVE-2016-7148?
To fix CVE-2016-7148, update MoinMoin to version 1.9.9 or later.
3
What does CVE-2016-7148 affect?
CVE-2016-7148 affects MoinMoin version 1.9.8, allowing for remote JavaScript injection attacks.
4
Can CVE-2016-7148 be exploited remotely?
Yes, CVE-2016-7148 can be exploited remotely by attackers using the page creation feature.
5
What type of vulnerability is CVE-2016-7148?
CVE-2016-7148 is a Cross Site Scripting (XSS) vulnerability.