{"id":"CVE-2004-0708","aliases":["GHSA-7jrp-r6jx-32cw","PYSEC-2026-671"],"title":"MoinMoin allows administrative access","summary":"MoinMoin allows administrative access","severity":"high","vendor":"moin","product":"moin","ecosystem":"pip","affected":["moin < 1.2.2"],"patched":["moin 1.2.2"],"published":"2022-04-29","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7jrp-r6jx-32cw","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0708"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16465"},{"url":"http://secunia.com/advisories/11807"},{"url":"http://sourceforge.net/tracker/index.php?func=detail&aid=948103&group_id=8482&atid=108482"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml"},{"url":"http://www.osvdb.org/6704"},{"url":"http://www.securityfocus.com/bid/10568"}],"tags":["osv","pip"],"epss":0.01767,"epssPercentile":0.7677,"ingestedAt":"2026-07-08T18:25:47.037Z","slug":"CVE-2004-0708","body":"## Overview\n\nMoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.\n\n## Affected packages\n\n- `moin < 1.2.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `moin 1.2.2`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}