CVE-2008-5846: Medium severity Sixapart Movable Type vulnerability
Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Six Apart Movable Typeto a version that resolves this vulnerability.Fixed in 4.23
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5846?
CVE-2008-5846 is classified as a moderate vulnerability that allows authenticated users to publish posts outside their intended access permissions.
How do I fix CVE-2008-5846?
To fix CVE-2008-5846, you should upgrade Movable Type to version 4.23 or later.
Who is affected by CVE-2008-5846?
CVE-2008-5846 affects users of Six Apart Movable Type versions prior to 4.23 and specific older versions such as 3.x.
What type of vulnerability is CVE-2008-5846?
CVE-2008-5846 is an access control vulnerability that allows unauthorized publishing of posts.
Can CVE-2008-5846 be exploited remotely?
Yes, CVE-2008-5846 can be exploited by remote authenticated users with certain permissions.