6.5
CVE-2022-45113
- EPSS 0.61%
- Veröffentlicht 07.12.2022 04:15:11
- Zuletzt bearbeitet 23.04.2025 16:15:27
- Erkennungen
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may allow a remote unauthenticated attacker to set a specially crafted URL to the Reset Password page and conduct a phishing attack. Affected products/versions are as follows: Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable Type Advanced 6.8.7 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sixapart ≫ Movable Type SwEdition premium Version <= 1.53
Sixapart ≫ Movable Type SwEdition premium_advanced Version <= 1.53
Sixapart ≫ Movable Type SwEdition - Version >= 6.0 < 6.8.7
Sixapart ≫ Movable Type SwEdition advanced Version >= 6.0 < 6.8.7
Sixapart ≫ Movable Type SwEdition - Version >= 7.0 < 7.9.6
Sixapart ≫ Movable Type SwEdition advanced Version >= 7.0 < 7.9.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.444 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://jvn.jp/en/jp/JVN37014768/index.html
https://movabletype.org/news/2022/11/mt-796-688-released.html