The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
{ "urgency": "low" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2008-6548.json"