-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
While the exact function isn't explicitly named in available resources, the vulnerability description specifically implicates the link dialogue in the GUI editor. XSS vulnerabilities typically occur when user input isn't properly sanitized before being rendered. The SecurityFixes page confirms 1.9.8 patched this by addressing improper input handling in this component. The medium confidence reflects the lack of direct commit/line-number evidence, but the specific component identification (link dialogue) and XSS pattern make this a reasonable conclusion.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moin | pip | < 1.9.8 | 1.9.8 |
Ongoing coverage of React2Shell