Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in Six Apart Movable Type 5.0 and 5.01 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
| Software | From | Fixed in |
|---|---|---|
| sixapart / movable_type | 5.01 | 5.01.x |
| sixapart / movable_type | 5.0 | 5.0.x |