Cross-Site Scripting Vulnerability in Movable Type by Six Apart
CVE-2020-5575

6.1MEDIUM

Key Information:

Vendor
CVE Published:
14 May 2020

Summary

A cross-site scripting vulnerability in Movable Type allows remote attackers to inject arbitrary scripts or HTML through unspecified vectors. This flaw affects several versions of Movable Type and its advanced variants, enabling potential exploitation that could compromise user data or manipulate web content. Users of affected versions are highly encouraged to apply patches and updates to mitigate this security risk.

Affected Version(s)

Movable Type Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.