Improper Neutralization of Special Elements in Output Used by a Downstream Component in Six Apart Ltd products - CVE-2020-5574
Published: May 14, 2020
Vulnerability identifier: #VU27916
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5574
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform cache poisoning attack.
The vulnerability exists due to improper input validation of HTML code. A remote attacker can send a specially crated request and inject arbitrary HTML attribute value.
Affected software
Movable Type Premium
Movable Type Premium Advanced
Movable Type
Movable Type Advanced
Movable Type for AWS
Movable Type Premium Advanced
Movable Type
Movable Type Advanced
Movable Type for AWS
How to mitigate CVE-2020-5574
Install updates from vendor's website.
Movable Type - addressed in versions 6.3.12, 6.6, 7.3
Movable Type Advanced - addressed in versions 6.3.12, 6.6.0, 7.3.0
Movable Type for AWS - update to 7.3.0
Movable Type Advanced - addressed in versions 6.3.12, 6.6.0, 7.3.0
Movable Type for AWS - update to 7.3.0