Six Apart Movable Type
cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*, +2 more
- <= 8.4.1
- <= 8.0.5
A reflected cross-site scripting vulnerability has been identified in Movable Type, affecting versions through 8.4.1 in the 8.4.x series, versions through 8.0.5 in the 8.0.x series, and several versions in the 2.x series. This vulnerability occurs on the user information edit page when the Multi-Factor Authentication plugin is enabled. A logged-in user who accesses a crafted page may have arbitrary scripts executed in their web browser.
Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browser of a logged-in user.
Users can upgrade to Movable Type 8.4.2, 8.0.6, or Movable Type Premium 2.07. For Movable Type Cloud Edition, version 8.5.0 is available. Instructions for downloading the latest version can be found on the Movable Type website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.