← Back

CVE-2023-45746

nvd nist
Published: Oct 30, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Premium 1.58 and earlier, Movable Type Premium Advanced 1.58 and earlier, Movable Type Cloud Edition (Version 7) r.5405 and earlier, and Movable Type Premium Cloud Edition 1.58 and earlier.

Affected (6)

1 product
Movable Type
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.902.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.902.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.59
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.59
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.902.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.59

References (4)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes

Timeline

No history available yet.