CVE-2020-5577: Malicious File Upload
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allow remote authenticated attackers to upload arbitrary files and execute a php script via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2020-5577
What is the severity of CVE-2020-5577?
The severity of CVE-2020-5577 is high with a severity value of 8.8.
Which software versions are affected by CVE-2020-5577?
Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type A…
What is the fix for CVE-2020-5577?
To fix CVE-2020-5577, update to Movable Type version 7.3.0, 6.6.0, or 6.3.12 depending on the version of Movable Type you are using.
Where can I find more information about CVE-2020-5577?
You can find more information about CVE-2020-5577 at the following references: [https://jvn.jp/en/jp/JVN28806943/index.html](https://jvn.jp/en/jp/JVN28806943/index.html), [https://movabletype.org/news/2020/05/mt-730-660-6312-released.html](https://movabletype.org/news/2020/05/mt-730-660-6312-released.html)