Loading
Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Use CWE-79, Sixapart vendor hub and Movabletype product page to widen CVE-2014-5313 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2010-4511, CVE-2010-4509 and CVE-2015-0845 for nearby disclosures in the same product family.