Executive brief
Movable Type, a popular content management system, contains a critical security flaw in its XML-RPC interface. This interface is used for remote communication and automated posting. An attacker can exploit this flaw to run unauthorized database commands, which could lead to the theft of sensitive data, modification of website content, or full system takeover. Organizations using affected versions should update to the latest patched releases immediately to prevent unauthorized access.
Technical details
A SQL injection vulnerability exists in the XML-RPC interface of Movable Type. The flaw is caused by improper neutralization of special elements used in SQL commands (CWE-89) within the XML-RPC handling logic. A remote, unauthenticated attacker can exploit this by sending specially crafted XML-RPC requests to the server. Successful exploitation allows the attacker to execute arbitrary SQL commands against the underlying database, potentially leading to full compromise of the application's data and administrative credentials. The issue affects Movable Type Pro/Advanced 6.x (prior to 6.1.3 and 6.2.6) and Open Source 5.2.13 and earlier. Patches are available in versions 6.1.3 and 6.2.6.
Affected products
- Six Apart Movable Type Pro 6.0.x, 6.1.x before 6.1.3, 6.2.x before 6.2.6
- Six Apart Movable Type Advanced 6.0.x, 6.1.x before 6.1.3, 6.2.x before 6.2.6
- Six Apart Movable Type Open Source 5.2.13 and earlier
Timeline
- 2016-06-22: advisory: Vendor advisory and release notes published by Six Apart
- 2016-06-22: disclosed: Public disclosure on oss-security mailing list
- 2017-01-23: advisory: NVD publication date