{"id":"GHSA-7jrp-r6jx-32cw","summary":"MoinMoin allows administrative access","details":"MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.","aliases":["CVE-2004-0708","PYSEC-2026-671"],"modified":"2026-07-06T08:11:25.543765727Z","published":"2022-04-29T02:58:13Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-09T16:04:59Z","nvd_published_at":"2004-07-27T04:00:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0708"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16465"},{"type":"WEB","url":"http://secunia.com/advisories/11807"},{"type":"WEB","url":"http://sourceforge.net/tracker/index.php?func=detail&aid=948103&group_id=8482&atid=108482"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml"},{"type":"WEB","url":"http://www.osvdb.org/6704"},{"type":"WEB","url":"http://www.securityfocus.com/bid/10568"}],"affected":[{"package":{"name":"moin","ecosystem":"PyPI","purl":"pkg:pypi/moin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-7jrp-r6jx-32cw/GHSA-7jrp-r6jx-32cw.json","last_known_affected_version_range":"\u003c= 1.2.1"}}],"schema_version":"1.9.0"}