CVE-2020-5574
MEDIUMMovable Type <7.2.1, <6.5.3, <6.3.11 - Code Injection
Title source: llmDescription
HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allows remote attackers to inject arbitrary HTML attribute value via unspecified vectors.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://movabletype.org/news/2020/05/mt-730-660-6312-released.html
Third Party Advisory, VDB Entry x_refsource_misc
https://jvn.jp/en/jp/JVN28806943/index.html
Scores
CVSS v3
5.3
EPSS
0.0121
EPSS Percentile
64.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-74
Status
published
Products (3)
sixapart/movable_type
< 1.29 (2 CPE variants)
sixapart/movable_type
6.3 - 6.3.11
sixapart/movable_type
7.0 - 7.2.1
Published
May 14, 2020
Tracked Since
Feb 18, 2026