Six Apart Movable Type
cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*, +3 more
- >= 8.0.0, <= 8.0.6
- >= 8.4.0, <= 8.4.2
- <= 7 r.5508
A vulnerability exists in Movable Type versions 8.0.0 to 8.0.6, 8.4.0 to 8.4.2, and several 7.0.x versions, allowing remote unauthenticated attackers to send tampered password reset emails. This issue arises from the application's use of less trusted sources, which could be exploited to manipulate email content related to password recovery.
Exploitation of this vulnerability could result in a remote unauthenticated attacker sending a fraudulent email to reset a user's password.
Users are advised to update to Movable Type 8.4.3, 8.0.7, or 7 r.5509. Movable Type Premium users should upgrade to version 2.10 or 1.67. For more information, visit the Movable Type release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.