CVE-2014-5313: XSS
Published Sep 10, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
5 affected components
Sixapart Movabletype<=5.14
Sixapart Movabletype=5.04
Sixapart Movabletype=5.11
Sixapart Movabletype=5.12
Sixapart Movabletype=5.13
Event History
Sep 10, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5313?
CVE-2014-5313 has a moderate severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-5313?
To fix CVE-2014-5313, upgrade Movable Type to version 5.2 or later.
3
Who is affected by CVE-2014-5313?
CVE-2014-5313 affects authenticated users of Six Apart Movable Type versions prior to 5.2.
4
What type of vulnerability is CVE-2014-5313?
CVE-2014-5313 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-5313 be exploited remotely?
Yes, CVE-2014-5313 can be exploited remotely by authenticated users.