#VU114232 Use of Less Trusted Source in Six Apart Ltd products - CVE-2025-53522
Published: August 20, 2025
Vulnerability identifier: #VU114232
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-53522
CWE-ID: CWE-348
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Movable Type
Movable Type Advanced
Movable Type Premium
Movable Type Cloud Edition
Movable Type Premium Cloud Edition
Movable Type Premium (Advanced Edition)
Movable Type
Movable Type Advanced
Movable Type Premium
Movable Type Cloud Edition
Movable Type Premium Cloud Edition
Movable Type Premium (Advanced Edition)
Software vendor:
Six Apart Ltd
Six Apart Ltd
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to use of less trusted source. A remote attacker can send a tampered email to reset a password.
Remediation
Install updates from vendor's website.