Use of Less Trusted Source in Six Apart Ltd products - CVE-2025-53522
Published: August 20, 2025
Vulnerability identifier: #VU114232
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-53522
CWE-ID: CWE-348
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Six Apart Ltd
Affected software:
Movable Type
Movable Type Advanced
Movable Type Premium
Movable Type Cloud Edition
Movable Type Premium Cloud Edition
Movable Type Premium (Advanced Edition)
Movable Type
Movable Type Advanced
Movable Type Premium
Movable Type Cloud Edition
Movable Type Premium Cloud Edition
Movable Type Premium (Advanced Edition)
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to use of less trusted source. A remote attacker can send a tampered email to reset a password.
How to mitigate CVE-2025-53522
Install updates from vendor's website.