#VU114233 Open redirect in Six Apart Ltd products - CVE-2025-55706
Published: August 20, 2025
Movable Type
Movable Type Advanced
Movable Type Premium
Movable Type Cloud Edition
Movable Type Premium Cloud Edition
Movable Type Premium (Advanced Edition)
Six Apart Ltd
Description
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.