Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
CVE-2020-25074 is a critical severity vulnerability with a CVSS score of 9.8. No known exploits currently, and patches are available.
Moderate probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
The cache action in action/cache.py allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
Users are strongly advised to upgrade to a patched version.
MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.
It is not advised to work around this, but to upgrade MoinMoin to a patched version.
That said, a work around via disabling the cache or the AttachFile action might be possible.
Also, it is of course helpful if you give write permissions (which include uploading attachments) only to trusted users.
This vulnerability was discovered by Michael Chapman.
If you have any questions or comments about this advisory, email me at [email protected].
| Vendor | Product |
|---|---|
| Moinmo | Moinmoin |
| Debian |
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.
| Debian Linux |