File Upload Vulnerability in Movable Type by Six Apart
CVE-2020-5577
Summary
The vulnerability in Movable Type products allows remote authenticated attackers to upload arbitrary files. By exploiting unspecified vectors, an attacker could execute malicious PHP scripts on the server, potentially compromising the integrity and security of the affected system. Users of Movable Type are urged to review their implementations and upgrade to the latest patched versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
Movable Type Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved