6

CVE-2012-4404

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoinmoMoinmoin Version1.9.0
MoinmoMoinmoin Version1.9.1
MoinmoMoinmoin Version1.9.2
MoinmoMoinmoin Version1.9.3
MoinmoMoinmoin Version1.9.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.762
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P