#VU27916 Improper Neutralization of Special Elements in Output Used by a Downstream Component in Six Apart Ltd products - CVE-2020-5574
Published: May 14, 2020
Vulnerability identifier: #VU27916
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-5574
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Movable Type
Movable Type Advanced
Movable Type for AWS
Movable Type Premium
Movable Type Premium Advanced
Movable Type
Movable Type Advanced
Movable Type for AWS
Movable Type Premium
Movable Type Premium Advanced
Software vendor:
Six Apart Ltd
Six Apart Ltd
Description
The vulnerability allows a remote attacker to perform cache poisoning attack.
The vulnerability exists due to improper input validation of HTML code. A remote attacker can send a specially crated request and inject arbitrary HTML attribute value.
Remediation
Install updates from vendor's website.