Open Redirect Vulnerability in Movable Type by Six Apart
CVE-2019-6025

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 December 2019

What is CVE-2019-6025?

This vulnerability in Movable Type allows remote attackers to exploit an open redirect, enabling them to redirect users to arbitrary websites. By crafting a malicious URL, attackers can conduct phishing attacks, potentially compromising user credentials and sensitive information. Affected versions include Movable Type 7, Movable Type 6.5, and Movable Type Premium, among others. Users are encouraged to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type Advanced 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type Advanced 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Premium 1.24 and earlier (Movable Type Premium), and Movable Type Premium (Advanced Edition) 1.24 and earlier (Movable Type Premium)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.