VYPR
Unrated severityNVD Advisory· Published Aug 26, 2021· Updated Aug 3, 2024

CVE-2021-20815

CVE-2021-20815

Description

Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting in Movable Type's Edit Boilerplate screen allows remote attackers to inject arbitrary script or HTML.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in the Edit Boilerplate screen of Movable Type. This flaw affects Movable Type 7 r.4903 and earlier (7 Series), Movable Type 6.8.0 and earlier (6 Series), Movable Type Advanced 7 r.4903 and earlier (Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier [1]. The vulnerability is triggered via unspecified vectors, allowing injection of arbitrary script or HTML.

Exploitation

An attacker can exploit this vulnerability by convincing a logged-in administrator or user with access to the Edit Boilerplate screen to interact with a crafted link or content. No authentication is required for the initial delivery, but the victim must be authenticated to the application for the injected script to execute in the context of their session [1]. The attack vector is network-based and requires user interaction (e.g., clicking a malicious link).

Impact

Successful exploitation allows the attacker to execute arbitrary script or HTML in the victim's browser within the security context of the affected Movable Type application. This can lead to session hijacking, defacement, or theft of sensitive information displayed on the page [1]. The CVSS v3 base score is 6.1 (Medium), with impacts on confidentiality and integrity, but not availability.

Mitigation

Six Apart released fixed versions: Movable Type 7 r.5001 (v7.8.0), Movable Type 6.8.1, and corresponding Advanced, Premium, and Premium Advanced updates [2]. Users should upgrade to these versions or later. No workarounds are documented; applying the vendor-supplied patch is the recommended mitigation [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Range: 7 r.4903 and earlier (7 Series), 6.8.0 and earlier (6 Series)
  • Range: 7 r.4903 and earlier
  • Range: 1.44 and earlier
  • Six Apart Ltd./Movable Typev5
    Range: Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.