Six Apart Movable Type
cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:*:*, +3 more
- >= 8.0.0, <= 8.0.6
- >= 8.4.0, <= 8.4.2
- <= 7 r.5508
An open redirect vulnerability has been identified in Movable Type, affecting versions 8.0.0 to 8.0.6, 8.4.0 to 8.4.2, and several versions in the 7 and 2 series. This vulnerability allows an attacker to insert an invalid parameter into the password reset page, potentially leading to redirection to an arbitrary URL.
Exploitation of this vulnerability could result in unauthorized redirection to a malicious site, potentially leading to phishing or other attacks.
Users are advised to update to Movable Type versions 8.4.3, 8.0.7, or 7 r.5509. For Movable Type Premium, version 2.10 or 1.67 should be installed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.