id: PYSEC-2013-23 details: Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link. affected: - package: name: moin ecosystem: PyPI purl: pkg:pypi/moin ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.9.6 versions: - 1.8.4 - 1.8.5 - 1.8.6 - 1.8.7 - 1.9.0 - 1.9.1 - 1.9.2 - 1.9.3 - 1.9.4 - 1.9.5 references: - type: WEB url: http://www.securityfocus.com/bid/57089 - type: WEB url: http://www.openwall.com/lists/oss-security/2012/12/29/7 - type: WEB url: http://hg.moinmo.in/moin/1.9/rev/c98ec456e493 - type: ADVISORY url: http://secunia.com/advisories/51663 - type: WEB url: http://www.openwall.com/lists/oss-security/2012/12/30/5 - type: WEB url: http://moinmo.in/SecurityFixes - type: ADVISORY url: https://github.com/advisories/GHSA-452h-rx28-49w9 aliases: - CVE-2012-6082 - GHSA-452h-rx28-49w9 modified: "2021-07-25T23:34:40.266603Z" published: "2013-01-03T01:55:00Z"