Six Apart Movable Type security update-CVE-2021-20837
NAME
Six Apart – Movable Type
- Platforms Affected:
Movable Type - Risk Level:
high - CVE Type:
OS command injection
DESCRIPTION
CVE-2021-20837 is an OS command injection vulnerability impacting multiple versions of Six Apart Movable Type. A Metasploit module was observed in open source and a proof of concept (PoC) was shared in the underground.
CVSS Information:
- CVSS 2.0 SCORE: 7.5
- CVSS 3.0 SCORE: 9.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://www[.]exploit-db[.]com/exploits/50464
MITIGATION
Six Apart addressed the vulnerability in a security advisory with updated versions.
- Reference Link:
https://movabletype.org/news/2021/10/mt-782-683-released.html - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.