Movable Type Open Redirect Vulnerability in Password Reset Functionality

Vulnerability

An open redirect vulnerability has been identified in Movable Type, affecting versions 8.0.0 to 8.0.6, 8.4.0 to 8.4.2, and several versions in the 7 and 2 series. This vulnerability allows an attacker to insert an invalid parameter into the password reset page, potentially leading to redirection to an arbitrary URL.

Impact

Exploitation of this vulnerability could result in unauthorized redirection to a malicious site, potentially leading to phishing or other attacks.

Remediation

Users are advised to update to Movable Type versions 8.4.3, 8.0.7, or 7 r.5509. For Movable Type Premium, version 2.10 or 1.67 should be installed.

Added: Aug 20, 2025, 5:19 AM
Updated: Aug 20, 2025, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.8
exploitability
6.5
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.