Cross-Site Scripting Vulnerability in Movable Type Products by Movable Type
CVE-2023-45746

5.4MEDIUM

What is CVE-2023-45746?

A cross-site scripting vulnerability exists in the Movable Type series that enables a remote authenticated attacker to inject arbitrary scripts. This could lead to the manipulation of user sessions or theft of sensitive information. Affected versions include several iterations of Movable Type, with critical updates required to mitigate these risks. The vulnerability affects Movable Type 7 r.5405 and earlier, Movable Type Advanced 7 r.5405 and earlier, as well as multiple Premium and Cloud editions of the software.

Affected Version(s)

Movable Type 7 (Movable Type 7 Series) r.5405 and earlier

Movable Type Advanced 7 (Movable Type 7 Series) r.5405 and earlier

Movable Type Cloud Edition (Version 7) r.5405 and earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.