Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.
https://movabletype.org/news/2015/04/movable_type_608_and_5213_released_to_close_security_vulnera.html
http://www.securitytracker.com/id/1032153
http://www.debian.org/security/2015/dsa-3227
Source: Mitre, NVD
Published: 2015-04-17
Updated: 2025-04-12
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.03359