CVE-2012-0317: Sixapart Movable Type

Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.

Affected products

  • Sixapart Movable Type: up to and including 4.37; version 4.28 only; version 4.29 only; version 4.36 only; version 4.291 only; version 4.292 only; …

Published 2012-03-03. Last modified 2026-06-16.