Lucene search

K
osvGoogleOSV:GHSA-RQXP-6926-HPHR
HistoryMay 01, 2022 - 11:45 p.m.

MoinMoin vulnerable to privilege escalation

2022-05-0123:45:03
Google
osv.dev
10
moinmoin
userform.py
privilege escalation
acls
superusers list
remote attackers
software

AI Score

7.5

Confidence

Low

EPSS

0.019

Percentile

88.4%

The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, which allows remote attackers to gain privileges.

AI Score

7.5

Confidence

Low

EPSS

0.019

Percentile

88.4%