CVE-2018-0672: XSS
Published Sep 4, 2018
·Updated
Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Sixapart Movable Type<6.3.1
Event History
Sep 4, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0672?
CVE-2018-0672 is a cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1.
2
How does CVE-2018-0672 affect Movable Type?
CVE-2018-0672 allows remote attackers to inject arbitrary web script or HTML into Movable Type.
3
How severe is CVE-2018-0672?
CVE-2018-0672 has a severity rating of 6.1 (medium).
4
How can I fix CVE-2018-0672 in Movable Type?
To fix CVE-2018-0672 in Movable Type, you should upgrade to version 6.3.1 or later.
5
Where can I find more information about CVE-2018-0672?
You can find more information about CVE-2018-0672 at http://jvn.jp/en/jp/JVN89550319/index.html.