Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-62499

Опубликовано: 23 окт. 2025
Источник: debian
EPSS Низкий

Описание

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
movabletype-opensourceremovedpackage

EPSS

Процентиль: 12%
0.00215
Низкий

Связанные уязвимости

CVSS3: 4.8
nvd
11 месяцев назад

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.

CVSS3: 4.8
github
11 месяцев назад

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.

EPSS

Процентиль: 12%
0.00215
Низкий