PT-2009-2018 · Moinmoin · Moinmoin
CVE-2008-6548
·
Publicado
2009-03-30
·
Atualizado
2024-02-02
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MoinMoin version 1.6.1
Description
The issue concerns the rst parser in MoinMoin, which fails to check the ACL of an included page. This allows attackers to read unauthorized include files via unknown vectors.
Recommendations
For MoinMoin version 1.6.1, consider restricting access to the
parser/text rst.py module to minimize the risk of exploitation until a patch is available.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Moinmoin