First published: Wed Feb 19 2025(Updated: )
Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Movable Type | ||
TinyMCE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24841 is classified as a high severity vulnerability due to its impact on user sessions through stored cross-site scripting.
To fix CVE-2025-24841, you should update to the latest version of Movable Type that addresses this vulnerability.
CVE-2025-24841 affects users of Movable Type when using TinyMCE6 as a rich text editor.
CVE-2025-24841 is a stored cross-site scripting vulnerability.
Yes, CVE-2025-24841 can be exploited remotely by executing an arbitrary script on a logged-in user's web browser.