CVE-2020-15275
Python vulnerability analysis and mitigation

Overview

MoinMoin, a wiki engine, was found to contain a stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2020-15275. The vulnerability, discovered by Catarina Leite from the Checkmarx SCA AppSec team, affects versions before 1.9.11. The issue was disclosed on November 8, 2020, and allows attackers with write permissions to upload SVG files containing malicious JavaScript code (GitHub Advisory).

Technical details

The vulnerability exists due to insufficient validation of SVG file uploads. When an attacker with write permissions uploads an SVG file containing malicious JavaScript, the code would be executed in users' browsers when viewing the SVG file on the wiki. The issue was addressed in version 1.9.11 by adding 'image/svg+xml' to the mimetypes_xss_protect list and including SVG in browser-supported images configuration (GitHub Commit).

Impact

When exploited, this vulnerability allows attackers to execute arbitrary JavaScript code in the context of other users' browsers when they view the malicious SVG file. This could lead to session hijacking, credential theft, or other client-side attacks against wiki users (MITRE CVE).

Exploitability

The vulnerability requires the attacker to have write permissions on the wiki, which includes the ability to upload attachments. This prerequisite somewhat limits the scope of potential attackers, but makes the vulnerability more likely to be exploited by insider threats or compromised accounts (GitHub Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade to MoinMoin version 1.9.11 or later, which contains the necessary security fixes. While not recommended as a permanent solution, temporary workarounds include implementing Content Security Policy (CSP) at the web server level and restricting write permissions to trusted users only (GitHub Advisory, Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84366HIGH7.4
  • Python logoPython
  • python-scrapy
NoYesSep 01, 2026
CVE-2026-53720MEDIUM5.1
  • Python logoPython
  • pymonocypher
NoYesSep 03, 2026
CVE-2026-84311MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
CVE-2026-84310MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
GHSA-wwv5-g3v4-889xLOW2.3
  • Python logoPython
  • tornado
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management