First published: Thu Aug 26 2021(Updated: )
Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Sixapart Movable Type | <=1.44 | |
Sixapart Movable Type | <=1.44 | |
Sixapart Movable Type | >=6.0<=6.8.0 | |
Sixapart Movable Type | >=7.0<7.8.0 | |
Sixapart Movable Type | >=7.0<7.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20808 is a cross-site scripting vulnerability in the Search screen of Movable Type, affecting versions 7 r.4903 and earlier (Movable Type 7 Series), 6.8.0 and earlier (Movable Type 6 Series), Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Premium 1.44 and earlier.
CVE-2021-20808 has a severity score of 6.1, which is considered medium.
CVE-2021-20808 affects Sixapart Movable Type versions 7 r.4903 and earlier (Movable Type 7 Series), 6.8.0 and earlier (Movable Type 6 Series), Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Premium 1.44 and earlier.
The Common Weakness Enumeration (CWE) ID for CVE-2021-20808 is CWE-79.
To fix the cross-site scripting vulnerability CVE-2021-20808, users should upgrade to Movable Type versions 7.8.0 or 6.8.1 or apply the patches provided by Sixapart.