CVE-2021-20809: XSS
Cross-site scripting vulnerability in Create screens of Entry, Page, and Content Type of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-20809.
What is the severity level of CVE-2021-20809?
The severity level of CVE-2021-20809 is medium.
What software versions are affected by CVE-2021-20809?
Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), and Movable Type Advanced 7 R.4002 and earlier (Movable Type Advanced 6 Series) are affected by CVE-2021-20809.
How can I fix CVE-2021-20809?
Upgrade to Movable Type 7.8.0, 6.8.1, 5.2.13, or the latest stable version from the official Movable Type website.
Where can I find more information about CVE-2021-20809?
You can find more information about CVE-2021-20809 at the official Movable Type website and the JVN website.