Cross-Site Scripting Vulnerability in Movable Type Products
CVE-2020-5528
What is CVE-2020-5528?
A cross-site scripting vulnerability exists in Movable Type products that allows remote attackers to inject arbitrary web scripts or HTML into the block editor and rich text editor. This can be exploited via a specially crafted URL, potentially compromising user data and site integrity. Affected versions include Movable Type 7 r.4603 and earlier, Movable Type 6.5.2 and earlier, and their advanced and premium counterparts, highlighting the importance of upgrading to the latest versions for enhanced security. For more details, you can refer to the official release notes and security advisories.
Affected Version(s)
Movable Type series Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type Premium Advanced)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved