Use of Less Trusted Source in Six Apart Ltd products - CVE-2025-53522
Published: August 20, 2025
Vulnerability identifier: #VU114232
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53522
CWE-ID: CWE-348
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to use of less trusted source. A remote attacker can send a tampered email to reset a password.
Affected software
Movable Type Premium (Advanced Edition)
Movable Type Advanced
Movable Type Premium
Movable Type
Movable Type Premium Cloud Edition
Movable Type Cloud Edition
Movable Type Advanced
Movable Type Premium
Movable Type
Movable Type Premium Cloud Edition
Movable Type Cloud Edition
How to mitigate CVE-2025-53522
Install updates from vendor's website.
Movable Type Premium (Advanced Edition) - addressed in versions 1.67, 2.10
Movable Type Advanced - addressed in versions r.5509, 8.0.7, 8.4.3
Movable Type Premium - addressed in versions 1.67, 2.10
Movable Type - addressed in versions r.5509, 8.0.0, 8.4.3
Movable Type Premium Cloud Edition - addressed in versions 1.67, 2.10
Movable Type Cloud Edition - addressed in versions r.5509, 8.7.0
Movable Type Advanced - addressed in versions r.5509, 8.0.7, 8.4.3
Movable Type Premium - addressed in versions 1.67, 2.10
Movable Type - addressed in versions r.5509, 8.0.0, 8.4.3
Movable Type Premium Cloud Edition - addressed in versions 1.67, 2.10
Movable Type Cloud Edition - addressed in versions r.5509, 8.7.0