Cross-Site Scripting Vulnerability in Movable Type by Six Apart
CVE-2021-20809

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 August 2021

Summary

A vulnerability in Movable Type exists that permits remote attackers to execute arbitrary scripts or HTML code in the Create screens of Entry, Page, and Content Type. This security flaw can be exploited through unspecified vectors, posing risks to web application integrity and user data. Affected versions include Movable Type 7 r.4903 and earlier, Movable Type 6.8.0 and earlier, Movable Type Advanced 7 r.4903 and earlier, and both Movable Type Premium 1.44 and earlier as well as Movable Type Premium Advanced 1.44 and earlier.

Affected Version(s)

Movable Type Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.