First published: Thu May 14 2020(Updated: )
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allow remote authenticated attackers to upload arbitrary files and execute a php script via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | <=1.29 | |
Sixapart Movable Type | <=1.29 | |
Sixapart Movable Type | >=6.3<=6.3.11 | |
Sixapart Movable Type | >=6.3<=6.3.11 | |
Sixapart Movable Type | >=6.5.0<=6.5.3 | |
Sixapart Movable Type | >=6.5.0<=6.5.3 | |
Sixapart Movable Type | >=7.0<=7.2.1 | |
Sixapart Movable Type | >=7.0<=7.2.1 | |
Sixapart Movable Type | >=7.0<=7.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5577
The severity of CVE-2020-5577 is high with a severity value of 8.8.
Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type A…
To fix CVE-2020-5577, update to Movable Type version 7.3.0, 6.6.0, or 6.3.12 depending on the version of Movable Type you are using.
You can find more information about CVE-2020-5577 at the following references: [https://jvn.jp/en/jp/JVN28806943/index.html](https://jvn.jp/en/jp/JVN28806943/index.html), [https://movabletype.org/news/2020/05/mt-730-660-6312-released.html](https://movabletype.org/news/2020/05/mt-730-660-6312-released.html)