VDB
Sign up
—

PYSEC-2009-11

Details

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/moin
Introduced in: 0

No fixed version published yet for moin (pip). Pin to a known-safe version or switch to an alternative.

References