PublicCVE

CVE-2020-5669

UNRATEDJSON exportCreate alert

Description

Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

Affected products

  • Six Apart Ltd. / Movable TypeMovable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier – Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier