MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
{
"severity": "MODERATE",
"github_reviewed_at": "2024-04-29T16:46:57Z",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": "2016-11-10T17:59:00Z",
"github_reviewed": true
}