CVE-2013-0209: Sixapart Movable Type
High severity, CVSS 7.5. EPSS: 45.2% chance of exploitation in the next 30 days.
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.
Affected products
- Sixapart Movable Type: version 4.21 only; version 4.22 only; version 4.23 only; version 4.24 only; version 4.25 only; version 4.26 only; …
Published 2013-01-23. Last modified 2026-06-16.