Impact
An SQL Injection flaw was identified in the Site Search feature of Movable Type, allowing an unauthenticated user to submit crafted input that is incorporated directly into a database query. The flaw can be exploited to run arbitrary SQL statements, potentially leading to full data compromise, unauthorized data retrieval, or subsequent privilege escalation. The weakness corresponds to CWE‑89.
Affected Systems
The affected software includes Six Apart Ltd.’s Movable Type suite, specifically Movable Type, Movable Type Cloud Edition, Movable Type Premium, and Movable Type Premium Cloud Edition. No version information was provided in the CVE data, so all released variants prior to the published fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity, ranking this vulnerability as high risk. While no EPSS value is available, the lack of listing in the CISA KEV catalog suggests no widely known exploits are currently distributed. The exploit requires only sending a crafted HTTP request to the search endpoint, and no authentication is required. Consequently, the risk of exposure remains significant for sites that enable Site Search, particularly those exposed to the public internet.
OpenCVE Enrichment