File Upload Vulnerability in Movable Type by Six Apart
CVE-2020-5577

8.8HIGH

Key Information:

Vendor
CVE Published:
14 May 2020

Summary

The vulnerability in Movable Type products allows remote authenticated attackers to upload arbitrary files. By exploiting unspecified vectors, an attacker could execute malicious PHP scripts on the server, potentially compromising the integrity and security of the affected system. Users of Movable Type are urged to review their implementations and upgrade to the latest patched versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Movable Type Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.