VDB
Sign up
—

PYSEC-2011-6

Quick fix

PYSEC-2011-6 — moin: upgrade to the fixed version with the command below.

pip install --upgrade 'moin>=1.9.3'

Details

Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the refuri attribute. NOTE: some of these details are obtained from third party information.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/moin
Introduced in: 0Fixed in: 1.9.3
Fixpip install --upgrade 'moin>=1.9.3'

References