CVE Published: 05/03/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jpcert |
Vendor: Six Apart Ltd. |
Product: Movable Type Status : PUBLISHED
CVE-2021-20665 Description
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.