Back to CVE List

CVE-2026-24447

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Vulnerability Description

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-1236
Source
NVD
Vendor
Six Apart Ltd.
Product
Movable Type (Software Edition), Movable Type Advanced (Software Edition), Movable Type Premium (Software Edition), Movable Type Premium (Advanced Edition) (Software Edition), Movable Type (Cloud Edition), Movable Type Premium (Cloud Edition)

External References

Discussion (0)

Add Comment

No comments yet. Be the first!