Cross-Site Scripting Vulnerability in Movable Type ContentType Information Widget Plugin
CVE-2021-20814
6.1MEDIUM
Summary
A cross-site scripting vulnerability exists in the Setting screen of the ContentType Information Widget Plugin for Movable Type, allowing remote attackers to inject arbitrary scripts or HTML. This issue affects Movable Type versions 7 r.4903 and earlier, Movable Type Advanced versions 7 r.4903 and earlier, and Movable Type Premium version 1.44 and earlier. Attackers could exploit this vulnerability through unspecified vectors, leading to potential unauthorized access and manipulation of web content.
Affected Version(s)
Movable Type Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Movable Type Premium 1.44 and earlier
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved