Cross-Site Scripting Vulnerability in Movable Type by Six Apart
CVE-2020-5575
Summary
A cross-site scripting vulnerability in Movable Type allows remote attackers to inject arbitrary scripts or HTML through unspecified vectors. This flaw affects several versions of Movable Type and its advanced variants, enabling potential exploitation that could compromise user data or manipulate web content. Users of affected versions are highly encouraged to apply patches and updates to mitigate this security risk.
Affected Version(s)
Movable Type Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved