Lucene search

K
cveJpcertCVE-2020-5576
HistoryMay 14, 2020 - 2:15 a.m.

CVE-2020-5576

2020-05-1402:15:11
CWE-352
jpcert
web.nvd.nist.gov
85
cve-2020-5576
cross-site request forgery
csrf vulnerability
movable type
remote attackers
authentication hijacking
unspecified vectors
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

52.1%

Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

Affected configurations

Nvd
Node
sixapartmovable_typeRange1.29advanced
OR
sixapartmovable_typeRange1.29premium
OR
sixapartmovable_typeRange6.36.3.11-
OR
sixapartmovable_typeRange6.36.3.11advanced
OR
sixapartmovable_typeRange6.5.06.5.3-
OR
sixapartmovable_typeRange6.5.06.5.3advanced
OR
sixapartmovable_typeRange7.07.2.1aws
OR
sixapartmovable_typeRange7.07.2.1-
OR
sixapartmovable_typeRange7.07.2.1advanced
VendorProductVersionCPE
sixapartmovable_type*cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*
sixapartmovable_type*cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium:*:*:*
sixapartmovable_type*cpe:2.3:a:sixapart:movable_type:*:*:*:*:-:*:*:*
sixapartmovable_type*cpe:2.3:a:sixapart:movable_type:*:*:*:*:*:aws:*:*

CNA Affected

[
  {
    "product": "Movable Type",
    "vendor": "Six Apart Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for AWS 7), Movable Type 6.5.3 and earlier (Movable Type 6.5), Movable Type Advanced 6.5.3 and earlier (Movable Type Advanced 6.5), Movable Type 6.3.11 and earlier (Movable Type 6.3), Movable Type Advanced 6.3.11 and earlier (Movable Type 6.3), Movable Type Premium 1.29 and earlier, and Movable Type Premium Advanced 1.29 and earlier"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

52.1%

Related for CVE-2020-5576