PT-2009-2018 · Moinmoin · Moinmoin

CVE-2008-6548

·

Publicado

2009-03-30

·

Atualizado

2024-02-02

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MoinMoin version 1.6.1
Description The issue concerns the rst parser in MoinMoin, which fails to check the ACL of an included page. This allows attackers to read unauthorized include files via unknown vectors.
Recommendations For MoinMoin version 1.6.1, consider restricting access to the parser/text rst.py module to minimize the risk of exploitation until a patch is available.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6548
GHSA-JHXW-4HW4-MHH7
PYSEC-2009-11

Produtos afetados

Moinmoin