Movable Type contains a reflected cross-site scripting vulnerability in the...
Vulnerability Description
Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25054
Credits & Attribution
No credits recorded in the NVD database.
References
More from Six Apart Ltd.
View All →Affected Vendor
Six Apart Ltd.
View all reports →