URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Six Apart Ltd
Six Apart Ltd movable Type |
|
| Vendors & Products |
Six Apart Ltd
Six Apart Ltd movable Type |
Wed, 20 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL. | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-08-20T04:23:01.512Z
Updated: 2025-08-20T15:57:41.631Z
Reserved: 2025-08-14T05:29:33.614Z
Link: CVE-2025-55706
Updated: 2025-08-20T15:57:25.698Z
Status : Awaiting Analysis
Published: 2025-08-20T05:15:28.253
Modified: 2025-08-20T14:39:07.860
Link: CVE-2025-55706
No data.