The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| moin(PyPI) | 0 | 1.8.7 | N/A |
CVSS Metrics