CVE-2013-0209 is a critical authentication bypass vulnerability affecting Movable Type versions 4.2x and 4.3x through 4.38. The flaw in lib/MT/Upgrade.pm allows unauthenticated remote attackers to exploit database-migration functions, leading to eval injection and SQL injection. This enables the execution of arbitrary Perl code, as demonstrated by attacks against the core_drop_meta_for_table function. With a CVSS score of 7.5 and an EPSS score of 0.806, this vulnerability presents a high risk, allowing for full compromise of confidentiality, integrity, and availability. Exploit code, including a Metasploit module, is publicly available, indicating a high potential for exploitation, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.21CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:4.21:*:*:*:*:*:*:* | ||
4.22CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:4.22:*:*:*:*:*:*:* | ||
4.23CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:4.23:*:*:*:*:*:*:* | ||
4.24CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:4.24:*:*:*:*:*:*:* | ||
4.25CPE matchmatch criteria | cpe:2.3:a:sixapart:movable_type:4.25:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.