4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
6.1 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
0.001 Low
EPSS
Percentile
39.4%
Cross-site scripting vulnerability in Movable Type series (Movable Type 7
r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier
(Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable
Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type
Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type
Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type
Premium Advanced)) allows remote attackers to inject arbitrary web script
or HTML in the block editor and the rich text editor via a specially
crafted URL.
4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
6.1 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
0.001 Low
EPSS
Percentile
39.4%