Lucene search

K
osvGoogleOSV:CVE-2020-25074
HistoryNov 10, 2020 - 5:15 p.m.

CVE-2020-25074

2020-11-1017:15:12
Google
osv.dev
8
cache action
directory traversal
moinmoin
remote code execution
software
http request

AI Score

9.7

Confidence

High

EPSS

0.014

Percentile

86.9%

The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.

AI Score

9.7

Confidence

High

EPSS

0.014

Percentile

86.9%