PYSEC-2026-671
Dashboard / Vulnerabilities / PYSEC-2026-671
PYSEC-2026-671
Summary: MoinMoin allows administrative access
Details: MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.
References: https://nvd.nist.gov/vuln/detail/CVE-2004-0708, https://exchange.xforce.ibmcloud.com/vulnerabilities/16465, http://secunia.com/advisories/11807, http://sourceforge.net/tracker/index.php?func=detail&aid=948103&group_id=8482&atid=108482, http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml, http://www.osvdb.org/6704, http://www.securityfocus.com/bid/10568, https://pypi.org/project/moin, https://github.com/advisories/GHSA-7jrp-r6jx-32cw
Affected packages
Package
Name: moin
Purl: pkg:pypi/moin
Affected ranges
Type: ECOSYSTEM
Events:
