—
PYSEC-2013-23
Quick fix
PYSEC-2013-23 — moin: upgrade to the fixed version with the command below.
pip install --upgrade 'moin>=1.9.6'Details
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- http://www.securityfocus.com/bid/57089[WEB]
- http://www.openwall.com/lists/oss-security/2012/12/29/7[WEB]
- http://hg.moinmo.in/moin/1.9/rev/c98ec456e493[WEB]
- http://secunia.com/advisories/51663[ADVISORY]
- http://www.openwall.com/lists/oss-security/2012/12/30/5[WEB]
- http://moinmo.in/SecurityFixes[WEB]
- https://github.com/advisories/GHSA-452h-rx28-49w9[ADVISORY]