Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43660


Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are as follows: Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier.


Published

2022-12-07T04:15:10.900

Last Modified

2025-04-23T14:15:22.737

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-94
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sixapart movable_type ≤ 1.53 Yes
Application sixapart movable_type ≤ 1.53 Yes
Application sixapart movable_type < 7.9.6 Yes
Application sixapart movable_type < 7.9.6 Yes

References