PT-2011-4020 · Six Apart · Movable Type+1
Published
2011-11-03
·
Updated
2017-08-29
·
CVE-2011-2676
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
A-Form and A-Form bamboo versions prior to 1.3.6
A-Form and A-Form bamboo versions 2.x prior to 2.0.3
A-Form PC and PC/Mobile versions prior to 3.1
Description
The issue allows remote authenticated users to modify data without requiring administrative authentication. This is due to a lack of authentication requirement in plug-ins for Movable Type, which can be exploited via unspecified vectors.
Recommendations
For A-Form and A-Form bamboo versions prior to 1.3.6, update to version 1.3.6 or later.
For A-Form and A-Form bamboo versions 2.x prior to 2.0.3, update to version 2.0.3 or later.
For A-Form PC and PC/Mobile versions prior to 3.1, update to version 3.1 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
A-Form
Movable Type