« Volver al listado

CVE-2021-20665

Estado: ModificadaMedia (6.1)—

Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20665",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Six Apart Ltd.",
          "product": "Movable Type",
          "versions": [
            {
              "status": "affected",
              "version": "Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-03-05T10:15:12.847",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN66542874/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://movabletype.org/news/2021/02/mt-760-676-released.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN66542874/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://movabletype.org/news/2021/02/mt-760-676-released.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de tipo cross-site scripting en la pantalla de activo Add del campo Contents de Movable Type 7 r.4705 y anteriores (Movable Type 7 Series), Movable Type Advanced 7 r.4705 y anteriores (Movable Type Advanced 7 Series), Movable Type Premium versiones 1.39 y anteriores, y Movable Type Premium Advanced versiones 1.39 y anteriores, permiten a atacantes remotos inyectar un script arbitrario por medio de vectores no especificados"
    }
  ],
  "lastModified": "2026-06-17T03:34:12.750",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:movabletype:movable_type:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4E348C5-DD83-420E-B3ED-255BA0B63EAB",
              "versionEndIncluding": "7.4705"
            },
            {
              "criteria": "cpe:2.3:a:movabletype:movable_type_advanced:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00880E0E-D684-4CEB-8456-0974C050C57A",
              "versionEndIncluding": "7.4705"
            },
            {
              "criteria": "cpe:2.3:a:movabletype:movable_type_premium:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00701C5D-F374-4FE2-8617-9EE8708308C6",
              "versionEndIncluding": "1.39"
            },
            {
              "criteria": "cpe:2.3:a:movabletype:movable_type_premium_advanced:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F76DB403-8212-43C2-B82D-C045306F3C69",
              "versionEndIncluding": "1.39"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}