Movable Type XMLRPC flaw enables RCE
A critical command injection vulnerability in Movable Type's XMLRPC API lets remote attackers execute arbitrary Perl and OS commands.
Six Apart's Movable Type content management system contains a command injection vulnerability in its XMLRPC API that allows a remote, unauthenticated attacker to execute arbitrary Perl scripts, and by extension arbitrary OS commands, on the underlying server. IPA rates the flaw as critical (CVSS v3: 9.8) and notes that all versions of Movable Type from 4.0 onward, including versions that have reached end-of-support, are affected. PowerCMS, a CMS built on top of Movable Type, may also be impacted by the same vulnerability.
Given the severity and ease of remote exploitation, IPA urges administrators to apply vendor-supplied updates as soon as possible. Where patching is not immediately feasible, disabling the XMLRPC API functionality in Movable Type is recommended as a mitigating measure. No indicators of active exploitation, threat actors, or specific campaigns are described in this advisory; it is a vendor patch notice distributed by Japan's IPA security center.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/20220824-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free