Improper Neutralization of Special Elements in Output Used by a Downstream Component in Six Apart Ltd products - CVE-2020-5574
Published: May 14, 2020
Vulnerability identifier: #VU27916
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-5574
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Six Apart Ltd
Affected software:
Movable Type
Movable Type Advanced
Movable Type for AWS
Movable Type Premium
Movable Type Premium Advanced
Movable Type
Movable Type Advanced
Movable Type for AWS
Movable Type Premium
Movable Type Premium Advanced
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cache poisoning attack.
The vulnerability exists due to improper input validation of HTML code. A remote attacker can send a specially crated request and inject arbitrary HTML attribute value.
How to mitigate CVE-2020-5574
Install updates from vendor's website.