VDB
Sign up
—

PYSEC-2010-28

Quick fix

PYSEC-2010-28 — moin: upgrade to the fixed version with the command below.

pip install --upgrade 'moin>=1.9.3'

Details

Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a crafted URI.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/moin
Introduced in: 0Fixed in: 1.9.3
Fixpip install --upgrade 'moin>=1.9.3'

References