First published: Sat Jul 07 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2644.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
hazama MT4i | <=3.1 | |
Movable Type |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2642 is classified as a medium severity vulnerability due to its potential for cross-site scripting exploitation.
To fix CVE-2012-2642, upgrade the MT4i plugin to version 3.1 beta 5 or later.
CVE-2012-2642 affects the MT4i plugin version 3.1 beta 4 and earlier for Movable Type.
Yes, CVE-2012-2642 can allow attackers to inject malicious scripts, potentially leading to data theft.
Yes, CVE-2012-2642 is a known vulnerability documented in public security databases.