The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://osvdb.org/48877 | vdb entry broken link |
http://moinmo.in/SecurityFixes | release notes vendor advisory |
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | broken link vendor advisory |