Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-45746


Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Premium 1.58 and earlier, Movable Type Premium Advanced 1.58 and earlier, Movable Type Cloud Edition (Version 7) r.5405 and earlier, and Movable Type Premium Cloud Edition 1.58 and earlier.


Published

2023-10-30T05:15:09.993

Last Modified

2024-11-21T08:27:17.743

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sixapart movable_type < 7.902.0 Yes
Application sixapart movable_type < 7.902.0 Yes
Application sixapart movable_type < 1.59 Yes
Application sixapart movable_type < 1.59 Yes
Application sixapart movable_type < 7.902.0 Yes
Application sixapart movable_type < 1.59 Yes

References