CPANSA-MT-2022-38078: MT vulnerability
Publisher |
giterlizzi |
Document category |
csaf_security_advisory |
Initial release date |
2022-08-24T00:00:00 |
Engine |
CSAF Perl Toolkit 0.25 |
Current release date |
2022-08-24T00:00:00 |
Build Date |
|
Current version |
1 |
Status |
final |
CVSS v3.1 Base Score |
9.8
|
Severity |
Critical
|
Original language |
|
Language |
en |
Also referred to |
|
Vulnerability Description
Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.
Vulnerabilities
CVE-2022-38078
Vulnerability DescriptionMovable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.
Weakness |
CWE-94 : Improper Control of Generation of Code ('Code Injection')
|
Product status
Known affected
Product |
Score |
MT greater than or equal 7 and less than or equal 7.9.4 |
|
MT greater than or equal 6 and less than or equal 6.8.6 |
|
MT greater than or equal 4 and less than or equal 5 |
|
Fixed
- MT greater than or equal 7.9.5
- MT greater than or equal 6.8.7 and less than 7
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
Revision history
Version |
Date of the revision |
Summary of the revision |
1 |
Wed Aug 24 00:00:00 2022 |
First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/