CVE-2026-24447
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.5 / 10
Vector String
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Vulnerability Description
If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-1236
Source
NVD
Vendor
Six Apart Ltd.
Product
Movable Type (Software Edition), Movable Type Advanced (Software Edition), Movable Type Premium (Software Edition), Movable Type Premium (Advanced Edition) (Software Edition), Movable Type (Cloud Edition), Movable Type Premium (Cloud Edition)
Discussion (0)
Add Comment
No comments yet. Be the first!