CVE-2021-20808: XSS
Cross-site scripting vulnerability in Search screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20808?
CVE-2021-20808 is a cross-site scripting vulnerability in the Search screen of Movable Type, affecting versions 7 r.4903 and earlier (Movable Type 7 Series), 6.8.0 and earlier (Movable Type 6 Series), Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Premium 1.44 and earlier.
What is the severity of CVE-2021-20808?
CVE-2021-20808 has a severity score of 6.1, which is considered medium.
How does CVE-2021-20808 affect Sixapart Movable Type?
CVE-2021-20808 affects Sixapart Movable Type versions 7 r.4903 and earlier (Movable Type 7 Series), 6.8.0 and earlier (Movable Type 6 Series), Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Premium 1.44 and earlier.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-20808?
The Common Weakness Enumeration (CWE) ID for CVE-2021-20808 is CWE-79.
How can I fix the cross-site scripting vulnerability CVE-2021-20808?
To fix the cross-site scripting vulnerability CVE-2021-20808, users should upgrade to Movable Type versions 7.8.0 or 6.8.1 or apply the patches provided by Sixapart.