Community Blog

Movable Type 5.13, 5.07, and 4.38 were released as mandatory security updates. These updates resolve multiple vulnerabilities discovered in Movable Type 5.x and Movable Type 4.x. The vulnerabilities were found as a result of our internal security audit, except the one reported from Trustwave (TWSL2012-003). All users must upgrade to this latest release immediately.

Impact

5.13, 5.07, and 4.38 address the multiple vulnerabilities including:

  • OS Command Injection exists in the file management system, the most serious of which may lead to arbitrary OS command execution by a user who has a permission to sign-in to the admin script and also has a permission to upload files.
  • Session Hijack and CSRF exist in the commenting and the community script. A remote attacker could hijack the user session or could execute arbitrary script code on victim's browser under the certain circumstances.
  • XSS exists in templates where the variables are not escaped properly. A remote attacker could inject client-side script into web pages viewed by other users.
  • XSS exists in mt-wizard.cgi. This vulnerability was reported by Trustwave (TWSL2012-003)

Solution

Please upgrade to the latest versions of Movable Type 4 or Movable Type 5.

  • Movable Type Open Source 4.38
  • Movable Type Open Source 5.07
  • Movable Type Open Source 5.13
  • Movable Type 4.38( with Professional Pack, Community Pack)
  • Movable Type 5.07( with Professional Pack, Community Pack)
  • Movable Type 5.13( with Professional Pack, Community Pack)
  • Movable Type Enterprise 4.38
  • Movable Type Advanced 5.13

Here are the release notes for this release.

Upgrading to Movable Type 5.13, 5.07, or 4.38

Download

You can download the latest packages from these sites ( What is the difference? ).

Firstly, follow the instructions found in Movable Type's upgrade guide to upgrade your Movable Type installation.

Refresh Templates

As a result of security fixes in Movable Type 5.13, 5.06 and 4.38, some of the global templates and JavaScript template in each blog were updated. You need to refresh those templates to comment or to use Community features once you upgrade to Movable Type 5.13, 5.07, 4.38, or later version. Please refer to the following documentation.

Here are the details of template changes.

Changes in Movable Type 5.13, 5.07, and 4.38

You can see the complete list of fixed bugs at this FogBugz page.

Following significant changes have been made in Movable Type 5.13, 5.07, and 4.38.

New features in Movable Type 5.13

Supported Browsers

Movable Type 5.13 supports the following browsers and versions.

  • Internet Explorer 9
  • Firefox latest
  • Safari latest

Security Enhancements

Movable Type 5.13 introduces the following security features.

  • Account and IP Lockout
    Account lockout is a feature to protect your Movable Type account from a password-guessing attack known as a brute force attack or a dictionary attack. Movable Type locks out accounts after defined number of incorrect password attempts.
  • Changing Password Validation Rules
    A system administrator can set password validation policies to let users to use stronger passwords.
  • Stronger Password Encryption

23 Comments

I love this new version. Great Work

Really nice work, good to know that MT is better protected against force attack.

Thx. Nice work Jun !

Great improvements from the previous versions. I like this new versions very much.
lifecell review site

I was waiting for these security updates. Thanks. :)

I am glade to read this, Thank you so much for providing individuals with such a breathtaking opportunity to read from this blog. It is always very enjoyable.

Last month, I wrote a blog that emerged from a catechism that I aboriginal airish in a LinkedIn altercation appointment for associates of the Medical Device Inventors ... mba application essays

I agree with you, just updated to the latest version and I'm very happy with the improvements.

This is little bit very important for the user.And more apparently I was very impressed by this.

nice article enjoyed while reading it

great update,now i finially hear the good new.

I like open source,i support open source,cheering..

If some one desires to be updated with latest technologies afterward he must be go to see this web page and be up to date everyday.

Greetings! This is my first visit to your blog! We are a collection of volunteers and starting a new project in a community in the same niche. Your blog provided us useful information to work on. You have done a wonderful job!

Thanks for sharing this information, it really helped me a lot.
mallorca yachts

There are a lot of blogs and articles out there on this topic, but you have captured another side of the subject. This is reliable content thank you for sharing it.

Glad to be a guest of your blog, I seem to be forward to more good articles and I think we all love to thank so many fine articles, blog to share with us.

Having useful information from your site for quite a few months now. Thank you. These pots are suitable for solid plate, glass/ceramic, radiant ring, halogen and gas stoves.

I am glad to catch idea from your article. It has information I have been searching for a long time. This looks absolutely perfect.

site for quite a few months now. Thank you. These pots are suitable for solid plate, glass/ceramic, radiant ring, halogen and gas stoves.

Thank you all gyes for posting a meaningful article which is really related for useful post.

Really impressed! Everything is very open and very clear reason of issues. It contains truly news. Your website is very valuable. Thanks for sharing.

Thanks for share. I will download this version now

Leave a comment

Have a question? Please use the MT Forums. Notes submitted on documentation should pertain to tips & hints regarding documentation. Your note may be removed once its contents have been integrated into the body of the page.


Type the characters you see in the picture above.