First published: Thu May 14 2020(Updated: )
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | <=1.29 | |
Sixapart Movable Type | <=1.29 | |
Sixapart Movable Type | >=6.3<=6.3.11 | |
Sixapart Movable Type | >=6.3<=6.3.11 | |
Sixapart Movable Type | >=6.5.0<=6.5.3 | |
Sixapart Movable Type | >=6.5.0<=6.5.3 | |
Sixapart Movable Type | >=7.0<=7.2.1 | |
Sixapart Movable Type | >=7.0<=7.2.1 | |
Sixapart Movable Type | >=7.0<=7.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5575 is a cross-site scripting vulnerability in Movable Type series.
CVE-2020-5575 affects Movable Type 7 r.4606 (7.2.1) and earlier, Movable Type Advanced 7 r.4606 (7.2.1) and earlier, Movable Type for AWS 7 r.4606 (7.2.1) and earlier, Movable Type 6.5.3 and earlier, and Movable Type Advanced 6.5.3 and earlier.
The severity level of CVE-2020-5575 is medium with a CVSS score of 6.1.
To fix CVE-2020-5575, it is recommended to upgrade to Movable Type version 7.3.0, 6.6.0, or 6.3.12.
Additional information about CVE-2020-5575 can be found at the following references: [JVN28806943](https://jvn.jp/en/jp/JVN28806943/index.html), [Movable Type News](https://movabletype.org/news/2020/05/mt-730-660-6312-released.html).