CVE-2013-2184

high
Published 2015-03-27 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://movabletype.org/documentation/appendices/release-notes/movable-type-526-release-notes.html

Application impact

VendorProductVersionsFixed
sixapartmovable_type{"endIncluding":"5.2.5"}

References

CWEs

CWE-17

Verify integrity in audit chain (admin only). AS-IS.