CVE-2021-20812

Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series) and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Date published : 2021-08-25

https://jvn.jp/en/jp/JVN97545738/index.html

https://movabletype.org/news/2021/08/mt-780-681-released.html