CVE-2021-20815
Description
Cross-site scripting vulnerability in Edit Boilerplate screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting in Movable Type's Edit Boilerplate screen allows remote attackers to inject arbitrary script or HTML.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in the Edit Boilerplate screen of Movable Type. This flaw affects Movable Type 7 r.4903 and earlier (7 Series), Movable Type 6.8.0 and earlier (6 Series), Movable Type Advanced 7 r.4903 and earlier (Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier [1]. The vulnerability is triggered via unspecified vectors, allowing injection of arbitrary script or HTML.
Exploitation
An attacker can exploit this vulnerability by convincing a logged-in administrator or user with access to the Edit Boilerplate screen to interact with a crafted link or content. No authentication is required for the initial delivery, but the victim must be authenticated to the application for the injected script to execute in the context of their session [1]. The attack vector is network-based and requires user interaction (e.g., clicking a malicious link).
Impact
Successful exploitation allows the attacker to execute arbitrary script or HTML in the victim's browser within the security context of the affected Movable Type application. This can lead to session hijacking, defacement, or theft of sensitive information displayed on the page [1]. The CVSS v3 base score is 6.1 (Medium), with impacts on confidentiality and integrity, but not availability.
Mitigation
Six Apart released fixed versions: Movable Type 7 r.5001 (v7.8.0), Movable Type 6.8.1, and corresponding Advanced, Premium, and Premium Advanced updates [2]. Users should upgrade to these versions or later. No workarounds are documented; applying the vendor-supplied patch is the recommended mitigation [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: 7 r.4903 and earlier (7 Series), 6.8.0 and earlier (6 Series)
- Range: 7 r.4903 and earlier
- Range: 1.44 and earlier
- Six Apart Ltd./Movable Typev5Range: Movable Type 7 r.4903 and earlier (Movable Type 7 Series), Movable Type 6.8.0 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.44 and earlier, and Movable Type Premium Advanced 1.44 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN97545738/index.htmlmitrex_refsource_MISC
- movabletype.org/news/2021/08/mt-780-681-released.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.