Description
Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4746 | Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user. |
References
History
Wed, 19 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Feb 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Factor authentication plugin is enabled and a user accesses a crafted page while logged in to the affected product, an arbitrary script may be executed on the web browser of the user. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-02-19T14:53:01.685Z
Reserved: 2025-02-03T00:23:31.179Z
Link: CVE-2025-25054
Updated: 2025-02-19T14:52:49.873Z
Status : Deferred
Published: 2025-02-19T06:15:22.010
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-25054
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD