MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.9.8-1ubuntu1.16.04.1", "binary_name": "python-moinmoin" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-7148.json"