CNNVD-202602-741 Information

CNNVD ID

CNNVD-202602-741

CVE-2026-23704

  • CNNVD Published: 2026-02-04

Description (Chinese)

Movable Type是Movable Type公司的一个内容管理系统。 Movable Type存在代码问题漏洞,该漏洞源于非管理员用户可上传恶意文件,可能导致管理员浏览器执行任意脚本。

Description (English)

Movable Type is a content management system for Movable Type. There is a code gap in Movable Type, which stems from the fact that non-administer users can upload malicious documents, which may lead to any script being executed by the administrator browser.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

Movable Type

Published

2026-02-04

Last Modified

2026-02-24

References

https://jvn.jp/en/jp/JVN45405689/ https://www.sixapart.jp/movabletype/news/2026/02/04-1100.html https://movabletype.org/news/2026/02/mt-906-released.html https://access.redhat.com/security/cve/cve-2026-23704

Patch

https://movabletype.org/news/2026/02/mt-906-released.html

Share on: