CVE-2021-20665
Description
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting in Movable Type's Add asset screen allows arbitrary script injection via unspecified vectors.
Vulnerability
Movable Type 7 r.4705 and earlier, Movable Type Advanced 7 r.4705 and earlier, Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier contain a cross-site scripting vulnerability in the Add asset screen of the Contents field. An attacker can inject an arbitrary script via unspecified vectors [1].
Exploitation
An unauthenticated attacker can craft a malicious link or content that, when interacted with by a logged-in user (e.g., clicking a link or visiting a crafted page), triggers execution of the injected script in the user's browser. No special network position is required beyond typical web access [1].
Impact
Successful exploitation allows arbitrary script execution in the context of the logged-in user's session. This can lead to information disclosure (e.g., reading session cookies), modification of page content, or additional actions performed on behalf of the victim [1].
Mitigation
Update to the latest version: Movable Type 7 r.4706 (v7.6.0) or Movable Type Advanced 7 r.4706 for the 7 series; Movable Type 6.7.6 for the 6.7 series. The fixed versions were released on 2021-02-24 [2]. No workarounds have been published.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <= r.4705
- Range: <= r.4705
- Range: <= 1.39
- Six Apart Ltd./Movable Typev5Range: Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN66542874/index.htmlmitrex_refsource_MISC
- movabletype.org/news/2021/02/mt-760-676-released.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.