First published: Tue Sep 04 2018(Updated: )
Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | <6.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0672 is a cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1.
CVE-2018-0672 allows remote attackers to inject arbitrary web script or HTML into Movable Type.
CVE-2018-0672 has a severity rating of 6.1 (medium).
To fix CVE-2018-0672 in Movable Type, you should upgrade to version 6.3.1 or later.
You can find more information about CVE-2018-0672 at http://jvn.jp/en/jp/JVN89550319/index.html.