# Movable Type XMLRPC flaw enables RCE

Published: 2022-09-01 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/b9828d8f-57f7-5df5-9f00-838caa250154/movable-type-xmlrpc-flaw-enables-rce

> A critical command injection vulnerability in Movable Type's XMLRPC API lets remote attackers execute arbitrary Perl and OS commands.

Six Apart's Movable Type content management system contains a command injection vulnerability in its XMLRPC API that allows a remote, unauthenticated attacker to execute arbitrary Perl scripts, and by extension arbitrary OS commands, on the underlying server. IPA rates the flaw as critical (CVSS v3: 9.8) and notes that all versions of Movable Type from 4.0 onward, including versions that have reached end-of-support, are affected. PowerCMS, a CMS built on top of Movable Type, may also be impacted by the same vulnerability.

Given the severity and ease of remote exploitation, IPA urges administrators to apply vendor-supplied updates as soon as possible. Where patching is not immediately feasible, disabling the XMLRPC API functionality in Movable Type is recommended as a mitigating measure. No indicators of active exploitation, threat actors, or specific campaigns are described in this advisory; it is a vendor patch notice distributed by Japan's IPA security center.

## Mentioned in this report

- Vulnerabilities: CVE-2022-36328

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/20220824-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b9828d8f-57f7-5df5-9f00-838caa250154/movable-type-xmlrpc-flaw-enables-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
