CVE-2023-45746 - CVE House
Back to Database
Status published Unknown CVE-2023-45746

Cross-site scripting vulnerability in Movable Type series allows a remote...

Vulnerability Description

Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary script. Affected products/versions are as follows: Movable Type 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5405 and earlier (Movable Type 7 Series), Movable Type Premium 1.58 and earlier, Movable Type Premium Advanced 1.58 and earlier, Movable Type Cloud Edition (Version 7) r.5405 and earlier, and Movable Type Premium Cloud Edition 1.58 and earlier.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-45746

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Six Apart Ltd.

View all reports →

Affected Software

Movable Type 7 (Movable Type 7 Series), Movable Type Advanced 7 (Movable Type 7 Series), Movable Type Premium, Movable Type Premium Advanced, Movable Type Cloud Edition (Version 7), Movable Type Premium Cloud Edition
Vulnerable Versions:
r.5405 and earlier, 1.58 and earlier

Timeline

Official Publish: October 30th, 2023
Last Modified: October 29th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.