Ubuntu Security Notice USN-716-1 – Fernando Quintero discovered than MoinMoin did not properly sanitize its input when processing login requests, resulting in cross-site scripting (XSS) vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. Fernando Quintero discovered that MoinMoin did not properly sanitize its input when attaching files, resulting in cross-site scripting vulnerabilities. It was discovered that MoinMoin did not properly sanitize its input when processing user forms, editing pages, relaying error messages, or when attaching files.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74490/USN-716-1.txt
Source: https://packetstormsecurity.com/files/74490/Ubuntu-Security-Notice-716-1.html