-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability specifically references the 'action=fckdialog&dialog=attachment' endpoint. This endpoint handles attachment management in the FCKeditor component. The XSS occurs because user-controlled input (page name) is directly embedded into HTML responses without proper sanitization. The function responsible for rendering this dialog would be the logical point where unsanitized page names are incorporated into the UI, matching the described attack vectors (page creation and crafted URLs). Though exact code isn't available, the pattern matches common XSS vulnerabilities in web handlers that fail to escape template variables.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moin | pip | = 1.9.8 | 1.9.9 |
Ongoing coverage of React2Shell