Movable Type 5.11, 5.051, 4.361 were released as mandatory security updates. These updates resolve multiple vulnerabilities discovered in Movable Type 5.x and Movable Type 4.x. All users must upgrade to this latest release immediately.
The impact of the vulnerabilities ¶
A remote attacker could create, read or modify the contents in the system under certain circumstances.
Versions Affected ¶
- Movable Type Open Source 4.x
- Movable Type Open Source 5.x
- Movable Type 4.x ( with Professional Pack, Community Pack )
- Movable Type 5.x ( with Professional Pack, Community Pack )
- Movable Type Enterprise 4.x
Solution ¶
Please upgrade to the latest versions of Movable Type 4 or Movable Type 5.
- Movable Type Open Source 4.361
- Movable Type Open Source 5.051
- Movable Type Open Source 5.11
- Movable Type 4.361( with Professional Pack, Community Pack)
- Movable Type 5.051( with Professional Pack, Community Pack)
- Movable Type 5.11( with Professional Pack, Community Pack)
- Movable Type Enterprise 4.361
- Movable Type Advanced 5.11
Download
- Download Movable Type Open Source
- Download Movable Type Pro
- Download other packages (including MT5.051)
Installation/upgrade instructions
New features and fixed issues ¶
Please see the release notes for new features and fixed issues in Movable Type 5.11, 5.051, and 4.361.
- Movable Type 5.11 / 5.051 / 4.361 release notes
- A new configuration directive DeniedAssetFileExtensions was implemented in Movable Type 5.11, 5.051, and 4.361.
- A configuration directive AssetFileExtensions was implemented in Movable Type 4.361 ( Movable Type 5.01 and later versions already have this feature ).
- Other changes