Cross-Site Scripting Vulnerability in Movable Type by Six Apart
CVE-2021-20809
Summary
A vulnerability in Movable Type exists that permits remote attackers to execute arbitrary scripts or HTML code in the Create screens of Entry, Page, and Content Type. This security flaw can be exploited through unspecified vectors, posing risks to web application integrity and user data. Affected versions include Movable Type 7 r.4903 and earlier, Movable Type 6.8.0 and earlier, Movable Type Advanced 7 r.4903 and earlier, and both Movable Type Premium 1.44 and earlier as well as Movable Type Premium Advanced 1.44 and earlier.
Affected Version(s)
Movable Type Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved