| [Japanese] | 
| JVNDB-2020-000030 | 
| Multiple vulnerabilities in Movable Type | 
|
| 
 
Movable Type provided by Six Apart Ltd. contains multiple vulnerabilities listed below. * HTML attribute value injection vulnerability (CWE-74) - CVE-2020-5574
 * Cross-site scripting due to a flaw in processing multiple query strings (CWE-79) - CVE-2020-5575
 * Cross-site request forgery (CWE-352) - CVE-2020-5576
 * Unrestricted upload of file with specific extentions (CWE-434) - CVE-2020-5577
 
 The following researchers reported these vulnerabilities to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 
 CVE-2020-5574, CVE-2020-5575, CVE-2020-5576
 Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc.
 
 CVE-2020-5577
 Yuji Tounai of Mitsui Bussan Secure Directions, Inc.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 6.3 (Medium) [IPA Score]
 
    Attack Vector: NetworkAttack Complexity: LowPrivileges Required: LowUser Interaction: NoneScope: UnchangedConfidentiality Impact: LowIntegrity Impact: LowAvailability Impact: Low 
  CVSS V2 Severity:Base Metrics 6.5 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: LowAuthentication: Single InstanceConfidentiality Impact: PartialIntegrity Impact: PartialAvailability Impact: Partial 
  
The above CVSS base scores have been assigned for CVE-2020-5577
 | 
| 
 
  CVSS V3 Severity:Base Metrics:
4.7 (Medium) [IPA Score]
 
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Changed
Confidentiality Impact: None
Integrity Impact: Low
Availability Impact: None CVSS V2 Severity:Base Metrics: 
4.3 (Medium) 
[IPA Score]
Access Vector: Network
Access Complexity: Medium
Authentication: None
Confidentiality Impact: None
Integrity Impact: Partial
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2020-5574 
 | 
| 
 
  CVSS V3 Severity:Base Metrics:
6.1 (Medium) [IPA Score]
 
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Changed
Confidentiality Impact: Low
Integrity Impact: Low
Availability Impact: None CVSS V2 Severity:Base Metrics: 
2.6 (Low) 
[IPA Score]
Access Vector: Network
Access Complexity: High
Authentication: None
Confidentiality Impact: None
Integrity Impact: Partial
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2020-5575 
 | 
| 
 
  CVSS V3 Severity:Base Metrics:
4.3 (Medium) [IPA Score]
 
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: Required
Scope: Unchanged
Confidentiality Impact: None
Integrity Impact: Low
Availability Impact: None CVSS V2 Severity:Base Metrics: 
2.6 (Low) 
[IPA Score]
Access Vector: Network
Access Complexity: High
Authentication: None
Confidentiality Impact: None
Integrity Impact: Partial
Availability Impact: None
The above CVSS base scores have been assigned for CVE-2020-5576
 | 
|
| 
 
	
 | 
| 
 
	Six Apart, Ltd.
	
		Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7)Movable Type 6.5.3 and earlier (Movable Type 6.5)Movable Type 6.3.11 and earlier (Movable Type 6.3)Movable Type Advanced 6.3.11 およびそれ以前 (Movable Type Advanced 6.3系)Movable Type Advanced 6.5.3 およびそれ以前 (Movable Type Advanced 6.5系)Movable Type Advanced 7 r.4606 (7.2.1) およびそれ以前 (Movable Type Advanced 7系)Movable Type Premium 1.29 およびそれ以前Movable Type Premium Advanced 1.29 およびそれ以前Movable Type for AWS 7 r.4606 (7.2.1) およびそれ以前 (Movable Type for AWS 7系) | 
| 
 
	
 | 
|
| 
 
* A remote attacker may inject arbitrary HTML attribute value. - CVE-2020-5574* An arbitrary script may be executed on a logged in user's web browser. - CVE-2020-5575
 * If a user views a malicious page while logged in, unintended operations may be performed. - CVE-2020-5576
 * A user who can upload files may upload arbitrary files and execute php script. - CVE-2020-5577
 
 | 
|
| 
 
[Update the Software]Update the software to the latest version according to the information provided by the developer.
 | 
|
| 
 
	Six Apart, Ltd.
	
 | 
|
| 
 
	Cross-Site Request Forgery(CWE-352) [IPA Evaluation]Cross-site Scripting(CWE-79) [IPA Evaluation]No Mapping(CWE-Other) [IPA Evaluation] | 
|
| 
 
	CVE-2020-5574 CVE-2020-5575 CVE-2020-5576 CVE-2020-5577  | 
|
| 
 
	JVN : JVN#28806943 National Vulnerability Database (NVD) : CVE-2020-5574 National Vulnerability Database (NVD) : CVE-2020-5575 National Vulnerability Database (NVD) : CVE-2020-5576 National Vulnerability Database (NVD) : CVE-2020-5577  | 
|
| 
 
	[2020/05/13]Web page was published
 
 
 
 |