CVE-2020-5574

MEDIUM

Movable Type <7.2.1, <6.5.3, <6.3.11 - Code Injection

Title source: llm
STIX 2.1

Description

HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allows remote attackers to inject arbitrary HTML attribute value via unspecified vectors.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://movabletype.org/news/2020/05/mt-730-660-6312-released.html
Third Party Advisory, VDB Entry x_refsource_misc
https://jvn.jp/en/jp/JVN28806943/index.html

Scores

CVSS v3 5.3
EPSS 0.0121
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-74
Status published
Products (3)
sixapart/movable_type < 1.29 (2 CPE variants)
sixapart/movable_type 6.3 - 6.3.11
sixapart/movable_type 7.0 - 7.2.1
Published May 14, 2020
Tracked Since Feb 18, 2026