CVE-2020-5528: XSS
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type Premium Advanced)) allows remote attackers to inject arbitrary web script or HTML in the block editor and the rich text editor via a specially crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5528?
CVE-2020-5528 is a cross-site scripting vulnerability in Movable Type series.
Which software versions are affected by CVE-2020-5528?
Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5).
What is the severity of CVE-2020-5528?
The severity of CVE-2020-5528 is medium with a CVSS score of 6.1.
How can I fix the CVE-2020-5528 vulnerability?
To fix the CVE-2020-5528 vulnerability, update Movable Type to version 7.2.0, 6.5.3, or 6.3.11 or later.
Where can I find more information about CVE-2020-5528?
You can find more information about CVE-2020-5528 on the JVN website and the Movable Type release notes.