SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1497

The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by…

MEDIUM 4.0EPSS 1.85%

Does this matter?

Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.

Description

The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
1.85% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
movabletype/movable type open source · movabletype/movable type enterprise · movabletype/movable type advanced · movabletype/movable type pro
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.