CVE-2012-2642: XSS
Published Jul 7, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2644.
Affected Software
2 affected components
Hazama Mt4i<=3.1
Six Apart Movable Type
Event History
Jul 7, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2642?
CVE-2012-2642 is classified as a medium severity vulnerability due to its potential for cross-site scripting exploitation.
2
How do I fix CVE-2012-2642?
To fix CVE-2012-2642, upgrade the MT4i plugin to version 3.1 beta 5 or later.
3
Which software is affected by CVE-2012-2642?
CVE-2012-2642 affects the MT4i plugin version 3.1 beta 4 and earlier for Movable Type.
4
Can CVE-2012-2642 allow for data theft?
Yes, CVE-2012-2642 can allow attackers to inject malicious scripts, potentially leading to data theft.
5
Is CVE-2012-2642 a known vulnerability?
Yes, CVE-2012-2642 is a known vulnerability documented in public security databases.