CVE-2025-24841 Details
Description
Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser.
A stored cross-site scripting vulnerability has been identified in Movable Type, specifically in versions through 8.4.1 of the 8.4.x and 8.0.x series, as well as in Movable Type Premium 2.06 and earlier. This vulnerability occurs in the HTML edit mode of the MT Block Editor when TinyMCE6 is used as a rich text editor. It allows for the execution of arbitrary scripts in the web browser of a logged-in user.
Users are advised to update to Movable Type 8.4.2, 8.0.6, or Movable Type Premium 2.07. For detailed upgrade instructions, visit the Movable Type release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 19, 2025CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN48742353/ | [email protected] | AdvisoryBundleRemedy |
| https://www.movabletype.org/news/2025/02/mt-842-released.html | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Six Apart Movable Type | <= 8.4.1 (semver) <= 8.0.5 (semver) |
CPE
Remediation
| |
| Six Apart Movable Type Advanced | All versions |
CPE
Remediation
| |
| Six Apart Movable Type Premium | All versions |
CPE
Remediation
| |
| Six Apart Movable Type Premium Advanced | All versions |
CPE
Remediation
| |
| Six Apart Movable Type Cloud Edition | All versions |
CPE
Remediation
| |
| Six Apart Movable Type Premium Cloud Edition | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 19, 2025 | New CVE Received | [email protected] |
Volerion