
Cloud Vulnerability DB
A community-led vulnerabilities database
MoinMoin, a wiki engine, was found to contain a stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2020-15275. The vulnerability, discovered by Catarina Leite from the Checkmarx SCA AppSec team, affects versions before 1.9.11. The issue was disclosed on November 8, 2020, and allows attackers with write permissions to upload SVG files containing malicious JavaScript code (GitHub Advisory).
The vulnerability exists due to insufficient validation of SVG file uploads. When an attacker with write permissions uploads an SVG file containing malicious JavaScript, the code would be executed in users' browsers when viewing the SVG file on the wiki. The issue was addressed in version 1.9.11 by adding 'image/svg+xml' to the mimetypes_xss_protect list and including SVG in browser-supported images configuration (GitHub Commit).
When exploited, this vulnerability allows attackers to execute arbitrary JavaScript code in the context of other users' browsers when they view the malicious SVG file. This could lead to session hijacking, credential theft, or other client-side attacks against wiki users (MITRE CVE).
The vulnerability requires the attacker to have write permissions on the wiki, which includes the ability to upload attachments. This prerequisite somewhat limits the scope of potential attackers, but makes the vulnerability more likely to be exploited by insider threats or compromised accounts (GitHub Advisory).
The primary mitigation is to upgrade to MoinMoin version 1.9.11 or later, which contains the necessary security fixes. While not recommended as a permanent solution, temporary workarounds include implementing Content Security Policy (CSP) at the web server level and restricting write permissions to trusted users only (GitHub Advisory, Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."