First published: Thu Dec 26 2019(Updated: )
Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type Advanced 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type Advanced 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Premium 1.24 and earlier (Movable Type Premium), and Movable Type Premium (Advanced Edition) 1.24 and earlier (Movable Type Premium) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | >=6.0<=6.3.9 | |
Sixapart Movable Type | >=7.0<=7.1.3 | |
Sixapart Movable Type | =6.5.0 | |
Sixapart Movable Type | =6.5.1 | |
Sixapart Movable Type | <=1.24 | |
Sixapart Movable Type | <=1.24 | |
Sixapart Movable Type | >=6.0<=6.3.9 | |
Sixapart Movable Type | >=7.0<=7.1.3 | |
Sixapart Movable Type | =6.5.0 | |
Sixapart Movable Type | =6.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6025 is an open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier.
CVE-2019-6025 affects Sixapart Movable Type versions 6.3.x, 6.2.x, 6.1.x, 6.0.x, 7.0, and 7.1.3.
The severity of CVE-2019-6025 is medium with a CVSS score of 6.1.
To fix CVE-2019-6025, update to Movable Type versions 6.3.9, 6.5.0, 6.5.1, 7.1.4, or later.
You can find more information about CVE-2019-6025 on the JVN website and the Movable Type official website.